5.1
CVSSv2

CVE-2006-5838

Published: 10/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via the path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

newp news publication system 1.0.0

Exploits

source: wwwsecurityfocuscom/bid/20893/info NewP News Publishing system is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible NewP version 100 is v ...