Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-10-13T19:00:00
Updated: 2024-08-07T19:48:28.675Z
Reserved: 2006-10-13T00:00:00
Link: CVE-2006-5282
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-10-13T19:07:00.000
Modified: 2024-11-21T00:18:35.890
Link: CVE-2006-5282
Redhat
No data.