This application requires Javascript for optimal performance.

WMNews.Multiple.Remote.File.Include

Alias(es)

WMNews.Multiple.Remote.File.Include.A, WMNews.Multiple.Remote.File.Include.E, WMNews.Multiple.Remote.File.Include.D, WMNews.Multiple.Remote.File.Include.C, WMNews.Multiple.Remote.File.Include.B

Release Date

Jan 25, 2007

Severity

low

Impact

Arbitrary PHP code execution

Description

Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.

Affected Products

Mikael Software WMNews 0.5

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.
ComScripts Web site, WM-News at http://www.comscripts.com/scripts/php.wm-news.203.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4666

Reference/s

http://www.securityfocus.com/bid/19886 (BugTraq)

Reference: VID-13890