Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-3859. PoCs published by [GB].
AI-analyzed exploit summary The provided text describes a remote file inclusion vulnerability in Q-News, where unsanitized user input in the 'id' parameter allows arbitrary PHP code execution. The example URL demonstrates how an attacker could exploit this by including a remote file.
Description
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
Exploits (1)
The provided text describes a remote file inclusion vulnerability in Q-News, where unsanitized user input in the 'id' parameter allows arbitrary PHP code execution. The example URL demonstrates how an attacker could exploit this by including a remote file.