7.5
CVSSv2

CVE-2005-1054

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.

Vulnerable Product Search on Vulmon Subscribe to Product

moderngigabyte modernbill

Exploits

source: wwwsecurityfocuscom/bid/13086/info ModernBill is prone to a remote file include vulnerability The problem presents itself specifically when an attacker passes the location of a remote attacker-specified script through the 'newsphp' script ModernBill 43 and prior versions are vulnerable to this issue wwwexamplecom ...