PT-2007-5425 · Andreas Robertz · Andreas Robertz Phpnews
Kezzap66345
·
Published
2007-08-08
·
Updated
2017-09-29
·
CVE-2007-4232
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Andreas Robertz PHPNews version 0.93
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
format menue parameter in the admin/inc/change action.php file.Recommendations
For Andreas Robertz PHPNews version 0.93, consider restricting access to the admin/inc/change action.php file to minimize the risk of exploitation. Avoid using the
format menue parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Andreas Robertz Phpnews