PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Czarnews | Czaries_network | 1.12 (including) | 1.12 (including) |
Czarnews | Czaries_network | 1.13 (including) | 1.13 (including) |
Czarnews | Czaries_network | 1.14 (including) | 1.14 (including) |