This application requires Javascript for optimal performance.

MyNewsGroups.Layersmenu.INC.Remote.File.Inclusion

Release Date

Nov 16, 2011

Severity

low

Impact

Compromise of affected system.

Description

It indicates a possible exploit of a remote File Inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu package for MyNewsGroups, that may allow remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.

Affected Products

MyNewsGroups MyNewsGroups 0.6b

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3966

Reference/s

http://www.securityfocus.com/bid/19258 (BugTraq)

Reference: VID-29886