20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and priormailing list
http://marc.info/?l=bugtraq&m=107651585921958&w=2 CVE-2004-0132
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
Record summary
CVE-2004-0132 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBVisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File InclusionExploitDB exploitby Cedric CochinNot analyzed1 file
ExploitDBVisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File InclusionExploitDB exploitby Cedric CochinNot analyzed1 file
References
3ezcontents-multiple-file-include(15135)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15135 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0132