Record summary

CVE-2004-1796 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.

Description

PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBHotNews 0.7.2 - Remote File InclusionExploitDB exploitby team_eliteNot analyzed1 file
ExploitDB

PoC details
ExploitDBHotNews 0.x - 'hotnews-engine.inc.php3?config[header]' Remote File InclusionExploitDB exploitby OfficerrrNot analyzed1 file
ExploitDB

PoC details
ExploitDBHotNews 0.x - 'config[incdir]' Remote File InclusionExploitDB exploitby OfficerrrNot analyzed1 file
ExploitDB

PoC details

References

9