CVE-2009-0643
Published Feb 20, 2009
Last updated 7 years ago
Overview
- Description
- Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dminnich:simple_php_news:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43ECAF21-1F05-4D68-A261-12A1B578F51C" } ], "operator": "OR" } ] } ]