7.5
CVSSv2

CVE-2002-1887

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote malicious users to execute arbitrary PHP code via the l parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

gregory kokanosky phpmynewsletter 0.6.10

Exploits

source: wwwsecurityfocuscom/bid/5886/info A vulnerability has been discovered in phpMyNewsLetter Reportedly, it is possible to pass an attacker-specified file include location to a CGI paramter of the 'customizephp' script This may allow an attacker to execute arbitrary commands with the privileges of the webserver Additionally, a ...
Product : phpMyNewsletter Tested version : 0610 Website : gregorykokanoskyfreefr/phpmynewsletter/ Problem : include file PHP code : °°°°°°°°°° ---- /include/customizephp ---- <? $langfile = $l; include $l; ?> ---- /include/customizephp ---- Exploit : °°°°°°°°° [t ...