5
CVSSv2

CVE-2003-1292

Published: 31/12/2003 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote malicious users to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ashwebstudio ashnews 0.83

Exploits

################ DEVIL TEAM THE BEST POLISH TEAM ################# # # ashnews v083(pathtoashnews) - Remote File Include Vulnerabilities # Script site: devashwebstudiocom/ # dork: News powered by ashnews # Find by Kacper (Rahim) # Greetings; DragonHeart, Satan, Leito, Leon, Luzak, Adam, DeathSpeed, Drzewko, pepi # ~~~~~~~~~~~~~~~~~~~~~~~ ...