7.5
CVSSv2

CVE-2004-1427

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.

Vulnerable Product Search on Vulmon Subscribe to Product

korweblog korweblog 1.6.2cvs

korweblog korweblog 1.6.1