33824vdb entry
http://osvdb.org/33824 CVE-2007-1247
aWebNews 1.1 - 'listing.php?path_to_news' Remote File Inclusion
Record summary
CVE-2007-1247 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBaWebNews 1.1 - 'listing.php?path_to_news' Remote File InclusionExploitDB exploitby mostafa_ragabNot analyzed1 file
References
1033825vdb entry
http://osvdb.org/33825 24351Third-party advisory
http://secunia.com/advisories/24351 2365Third-party advisory
http://securityreason.com/securityalert/2365 20070301 aWebNews v 1.1=>RFImailing list
http://www.securityfocus.com/archive/1/461680/100/0/threaded 20070301 aWebNews V 1.1mailing list
http://www.securityfocus.com/archive/1/461684/100/0/threaded 22781vdb entry
http://www.securityfocus.com/bid/22781 ADV-2007-0808vdb entry
http://www.vupen.com/english/advisories/2007/0808 awebnews-pathtonews-file-include(32770)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/32770 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1247