5
CVSSv2

CVE-2005-0647

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

admin_setup.php in paNews 2.0.4b allows remote malicious users to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.

Vulnerable Product Search on Vulmon Subscribe to Product

php arena panews 2.0.4b

Exploits

/*************************************************** * * * paNews v20b4 * * * * silePNEWSxpl * * This exploit utilize SQL injection for create * * a new user with admin privileg ...