Vulnerabilities > CVE-2005-0859 - Remote File Include vulnerability in Czaries Network Czarnews 1.13B

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
czaries-network
exploit available

Summary

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

Vulnerable Configurations

Part Description Count
Application
Czaries_Network
1

Exploit-Db

  • descriptionCzarNews <= 1.14 (tpath) Remote File Inclusion Vulnerability. CVE-2005-0859,CVE-2006-3685. Webapps exploit for php platform
    fileexploits/php/webapps/2009.txt
    idEDB-ID:2009
    last seen2016-01-31
    modified2006-07-13
    platformphp
    port
    published2006-07-13
    reporterSHiKaA
    sourcehttps://www.exploit-db.com/download/2009/
    titleCzarNews <= 1.14 tpath Remote File Inclusion Vulnerability
    typewebapps
  • descriptionCzarNews 1.13/1.14 headlines.php Remote File Inclusion. CVE-2005-0859. Webapps exploit for php platform
    idEDB-ID:25244
    last seen2016-02-03
    modified2005-03-21
    published2005-03-21
    reporterbrOmstar
    sourcehttps://www.exploit-db.com/download/25244/
    titleCzarNews 1.13/1.14 headlines.php Remote File Inclusion