VulnerabilityModified
CVE-2006-4671
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter, a different vector than CVE-2006-1154.
MEDIUM 6.8EPSS 2.75%
Does this matter?
Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter, a different vector than CVE-2006-1154.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- fscripts/fantastic news
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21807Exploit, Vendor Advisory
- http://secunia.com/advisories/23519Vendor Advisory
- http://www.securityfocus.com/bid/21796
- http://www.vupen.com/english/advisories/2006/3513Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31121
- https://www.exploit-db.com/exploits/3027
- http://secunia.com/advisories/21807Exploit, Vendor Advisory
- http://secunia.com/advisories/23519Vendor Advisory
- http://www.securityfocus.com/bid/21796
- http://www.vupen.com/english/advisories/2006/3513Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31121
- https://www.exploit-db.com/exploits/3027
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.