MEDIUM
Multiple direct static code injection vulnerabilities in add_go.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via the (1) description, (2) issue, (3) title, (4) var, (5) name, (6) keywords, and (7) note parameters, which are stored in an article file
Published Sep 13, 2006
5.0
MEDIUMCVSS 2.0
EPSS 1.33%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.