20050414 All4WWW-Homepagecreator Remote Command Executionmailing list
http://marc.info/?l=bugtraq&m=111350434925520&w=2 CVE-2005-1117
All4WWW-HomePageCreator 1.0 - 'index.php' Remote File Inclusion
Record summary
CVE-2005-1117 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAll4WWW-HomePageCreator 1.0 - 'index.php' Remote File InclusionExploitDB exploitby Francisco AlissonNot analyzed1 file
References
414972Third-party advisory
http://secunia.com/advisories/14972 13169vdb entry
http://www.securityfocus.com/bid/13169 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1117