CVE-2005-0647

Publication date

2005-03-04 05:00:00

Family

mitre

State

PUBLISHED

Description

admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.