Description
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Filip Groszynski · textwebappsphp
https://www.exploit-db.com/exploits/864
References (2)
Core 2
Core References
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/12747
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/392552
Scores
EPSS
0.0061
EPSS Percentile
69.9%
Details
Status
published
Products (5)
jason_hines/phpweblog
0.4.2
jason_hines/phpweblog
0.5
jason_hines/phpweblog
0.5.1
jason_hines/phpweblog
0.5.2
jason_hines/phpweblog
0.5.3
Published
Mar 07, 2005
Tracked Since
Feb 18, 2026