CVE Vulnerabilities

CVE-2004-0132

Published: Mar 03, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.

Affected Software

Name Vendor Start Version End Version
Ezcontents Visualshapers 1.45 1.45
Ezcontents Visualshapers 2.0_rc2 2.0_rc2
Ezcontents Visualshapers 1.40 1.40
Ezcontents Visualshapers 1.41 1.41
Ezcontents Visualshapers 1.43 1.43
Ezcontents Visualshapers 1.45b 1.45b
Ezcontents Visualshapers 2.0.2 2.0.2
Ezcontents Visualshapers 2.0_rc1 2.0_rc1
Ezcontents Visualshapers 2.0.1 2.0.1
Ezcontents Visualshapers 2.0_rc3 2.0_rc3
Ezcontents Visualshapers 1.44 1.44
Ezcontents Visualshapers 1.42 1.42

References