7.5
CVSSv2

CVE-2002-2249

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote malicious users to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

Vulnerable Product Search on Vulmon Subscribe to Product

php evolution news evolution 1.0

php evolution news evolution 2.0

Exploits

source: wwwsecurityfocuscom/bid/6260/info News Evolution is a freely available, open source news software package It is written in PHP, and designed for use on Unix and Linux operating systems The problem occurs in the aff_newsphp file By loading this file, and defining the chemin variable to an arbitrary location, commands can be ex ...