PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/10551 - Patch | |
References | () http://securitytracker.com/id?1008608 - Exploit, Patch | |
References | () http://sourceforge.net/forum/forum.php?forum_id=342594 - Patch | |
References | () http://www.osvdb.org/3332 - | |
References | () http://www.osvdb.org/3405 - | |
References | () http://www.securityfocus.com/archive/1/348840 - Exploit, Patch | |
References | () http://www.securityfocus.com/bid/9357 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/14140 - |
Information
Published : 2004-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-1796
Mitre link : CVE-2004-1796
CVE.ORG link : CVE-2004-1796
JSON object : View
Products Affected
hotnews
- hotnews
CWE