MySimpleNews PHP Injection Vulnerability
BID:5865
Info
MySimpleNews PHP Injection Vulnerability
| Bugtraq ID: | 5865 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery credited to Frog Man <[email protected]>. |
| Vulnerable: |
MySimpleNews MySimpleNews 1.0 |
| Not Vulnerable: | |
Discussion
MySimpleNews PHP Injection Vulnerability
MySimpleNews allows users to enter news articles through a web interface. It will allow PHP code to be injected into URI parameters of the 'users.php' script, which will be stored into a MySimpleNews file (news.php3). The injected code may then be executed by the attacker by requesting the 'news.php3' script.
MySimpleNews allows users to enter news articles through a web interface. It will allow PHP code to be injected into URI parameters of the 'users.php' script, which will be stored into a MySimpleNews file (news.php3). The injected code may then be executed by the attacker by requesting the 'news.php3' script.