Vulnerabilities > CVE-2005-0698 - Remote File Include vulnerability in Jason Hines PHPWebLog

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
jason-hines
exploit available

Summary

PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.

Exploit-Db

descriptionphpWebLog <= 0.5.3 Arbitrary File Inclusion. CVE-2005-0698. Webapps exploit for php platform
idEDB-ID:864
last seen2016-01-31
modified2005-03-07
published2005-03-07
reporterFilip Groszynski
sourcehttps://www.exploit-db.com/download/864/
titlephpWebLog <= 0.5.3 - Arbitrary File Inclusion