7.5
CVSSv2

CVE-2004-1796

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in HotNews 0.7.2 and previous versions allows remote malicious users to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

Vulnerable Product Search on Vulmon Subscribe to Product

hotnews hotnews 0.7.2

hotnews hotnews 0.6.0

hotnews hotnews 0.6.0_pre

hotnews hotnews 0.6.1

hotnews hotnews 0.7.0

hotnews hotnews 0.7.1

hotnews hotnews 0.5.3

Exploits

================================================================================================ ================================================================================================ == @@@@@@@@ @@@@@@ @@@@@@@ @@ @@ @@@@@@ @@ @@ @@@@@@@@ @@@@@@ == == @@@@@@@@ @@@@@@ @@@@@@@ @@@ @@@ @@@@@@ ...
source: wwwsecurityfocuscom/bid/9357/info HotNews is prone to multiple file include vulnerabilities This will permit remote attackers to cause malicious PHP scripts from attacker-controlled servers to be included and subsequently executed in the context of the web server hosting the vulnerable software wwwexamplecom/includes/ ...
source: wwwsecurityfocuscom/bid/9357/info HotNews is prone to multiple file include vulnerabilities This will permit remote attackers to cause malicious PHP scripts from attacker-controlled servers to be included and subsequently executed in the context of the web server hosting the vulnerable software wwwexamplecom/includes/h ...