Vulnerabilities > CVE-2005-0800 - Unspecified vulnerability in Mcnews

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mcnews
exploit available

Summary

PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

Vulnerable Configurations

Part Description Count
Application
Mcnews
5

Exploit-Db

descriptionMcNews 1.x Install.PHP Arbitrary File Include Vulnerability. CVE-2005-0800. Webapps exploit for php platform
idEDB-ID:25232
last seen2016-02-03
modified2005-03-17
published2005-03-17
reporterJonathan Whiteley
sourcehttps://www.exploit-db.com/download/25232/
titleMcNews 1.x Install.PHP Arbitrary File Include Vulnerability