HIGH
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable
Published Mar 10, 2006
7.5
HIGHCVSS 2.0
EPSS 2.85%
Description
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable.
Affected products
No data.
OR
- 2.1.1
- 2.1.2
- 2.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://secunia.com/advisories/21807 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23519 third-party-advisoryx_refsource_SECUNIA
- http://sx02.coresec.de/advisories/152.txt x_refsource_MISC
- http://www.securityfocus.com/bid/16985 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/21796 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/0826 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/3513 vdb-entryx_refsource_VUPENVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1158 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25064 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31121 vdb-entryx_refsource_XF
- https://www.exploit-db.com/exploits/3027 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/21807 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/23519 | third-party-advisoryx_refsource_SECUNIA | |
| http://sx02.coresec.de/advisories/152.txt | x_refsource_MISC | |
| http://www.securityfocus.com/bid/16985 | vdb-entryx_refsource_BID | |
| http://www.securityfocus.com/bid/21796 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/0826 | vdb-entryx_refsource_VUPEN | |
| http://www.vupen.com/english/advisories/2006/3513 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1158 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25064 | vdb-entryx_refsource_XF | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/31121 | vdb-entryx_refsource_XF | |
| https://www.exploit-db.com/exploits/3027 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 10, 2006
Updated Aug 7, 2024
Reserved Mar 10, 2006
Link CVE-2006-1154
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1158 Assigner mitre
Published Mar 10, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1158