Security Advisory

CVE-2006-4768

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-09-13 23:00:00
Last updated 2024-08-07 19:23:41
Assigner mitre
State PUBLISHED

Description

Multiple direct static code injection vulnerabilities in add_go.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via the (1) description, (2) issue, (3) title, (4) var, (5) name, (6) keywords, and (7) note parameters, which are stored in an article file. NOTE: the original source of this vulnerability is unknown; the details are obtained from third party information and CVE post-disclosure analysis.