PT-2006-5543 · Stefan Ernst · Stefan Ernst Newsscript

Published

2006-09-13

·

Updated

2017-07-20

·

CVE-2006-4768

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Stefan Ernst Newsscript (aka WM-News) version 0.5 beta
Description The issue allows remote attackers to execute arbitrary PHP code via several parameters in the add go.php file. These parameters include description, issue, title, var, name, keywords, and note, which are stored in an article file.
Recommendations For Stefan Ernst Newsscript (aka WM-News) version 0.5 beta, consider restricting access to the add go.php file and avoid using the vulnerable parameters until a fix is available. As a temporary workaround, consider validating and sanitizing all user input for the description, issue, title, var, name, keywords, and note parameters to prevent code injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4768

Affected Products

Stefan Ernst Newsscript