Vulnerabilities > CVE-2006-3685 - Remote File Include vulnerability in Czaries Network Czarnews 1.12/1.13/1.14

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
czaries-network
exploit available

Summary

PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.

Vulnerable Configurations

Part Description Count
Application
Czaries_Network
3

Exploit-Db

descriptionCzarNews <= 1.14 (tpath) Remote File Inclusion Vulnerability. CVE-2005-0859,CVE-2006-3685. Webapps exploit for php platform
fileexploits/php/webapps/2009.txt
idEDB-ID:2009
last seen2016-01-31
modified2006-07-13
platformphp
port
published2006-07-13
reporterSHiKaA
sourcehttps://www.exploit-db.com/download/2009/
titleCzarNews <= 1.14 tpath Remote File Inclusion Vulnerability
typewebapps