20050829 SimplePHPBlog Arbitrary File Deletion and Sample Exploitmailing list
http://marc.info/?l=bugtraq&m=112534658510762&w=2 CVE-2005-2787
Simple PHP Blog 0.4.0 - Multiple Remote s
Record summary
CVE-2005-2787 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSimple PHP Blog 0.4.0 - Multiple Remote sExploitDB exploitby Kenneth BelvaNot analyzed1 file
References
616616Third-party advisory
http://secunia.com/advisories/16616 ftusecurity.com
http://www.ftusecurity.com/pub/sphpblog_vulns 14681vdb entry
http://www.securityfocus.com/bid/14681 simple-php-commentdeletecgi-file-deletion(22096)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/22096 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2787