PT-2009-3284 · Php · Simple Php News

Osirys

·

Published

2009-02-18

·

Updated

2017-09-29

·

CVE-2009-0643

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple PHP News version 1.0 final
Description The issue allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter in post.php, which can then be executed by making a direct request to "display.php".
Recommendations For Simple PHP News version 1.0 final, consider restricting access to the post parameter in post.php to prevent code injection, and avoid using the display.php endpoint to execute arbitrary code until a fix is available.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0643

Affected Products

Simple Php News