PT-2005-1757 · Php · Php Mcnews
Filip Groszynski
+1
·
Published
2005-03-08
·
Updated
2018-10-19
·
CVE-2005-0720
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP mcNews version 1.3
Description
A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code by modifying the
skinfile parameter to reference a URL on a remote web server that contains the code.Recommendations
For PHP mcNews version 1.3, consider restricting access to the
admin/header.php file or validating the skinfile parameter to prevent remote file inclusion attacks. As a temporary workaround, avoid using the skinfile parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Mcnews