7.5
CVSSv2

CVE-2006-5434

Published: 20/10/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote malicious users to execute arbitrary PHP code via a URL in the pn_lang parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

p-news p-news 1.16

p-news p-news 1.17

Exploits

============================================ P-News 116, 117 Remote File Inclusion Vulnerability ============================================ Discovered by vegas78 - feel82[at]webde ============================================ Greetz: scoper, corny, smaesch0r, Sascha Schmalz, ReFleCtion, BleX, |pupi (?), ============================ ...