7.5
CVSSv2

CVE-2006-1212

Published: 14/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote malicious users to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use a "page" parameter or variable.

Vulnerable Product Search on Vulmon Subscribe to Product

corenews corenews 2.0.1

Exploits

source: wwwsecurityfocuscom/bid/17067/info Core News is prone to a code-execution vulnerability An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the webserver process This may facilitate a compromise of the application and the underlying system; other attacks are also possible ...