Vulnerabilities > CVE-2005-0632 - Remote File Include vulnerability in PHPnews 1.2.3/1.2.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
phpnews
nessus
exploit available

Summary

PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

Vulnerable Configurations

Part Description Count
Application
Phpnews
2

Exploit-Db

descriptionPHPNews 1.2.3/1.2.4 Auth.PHP Remote File Include Vulnerability. CVE-2005-0632. Webapps exploit for php platform
idEDB-ID:25180
last seen2016-02-03
modified2005-03-01
published2005-03-01
reportermozako
sourcehttps://www.exploit-db.com/download/25180/
titlePHPNews 1.2.3/1.2.4 - Auth.PHP Remote File Include Vulnerability

Nessus

NASL familyCGI abuses
NASL idPHPNEWS_REMOTE_INCLUDES.NASL
descriptionThe remote host is running PHPNews, an open source news application written in PHP. The installed version of PHPNews has a remote file include vulnerability in the script
last seen2020-06-01
modified2020-06-02
plugin id17247
published2005-03-02
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17247
titlePHPNews auth.php path Parameter Remote File Inclusion