CVE-2012-1933
Newscoop 3.5.x < 3.5.5 and 4 < RC4 - Remote Code Execution via GLOBALS[g_campsiteDir] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1933. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Newscoop, including Remote File Inclusion (RFI), SQL Injection (SQLi), and Cross-Site Scripting (XSS). It provides Proof-of-Concept (PoC) URLs for each vulnerability but does not include executable exploit code.
Description
Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3) conf/liveuser_configuration.php.
Exploits (1)
This advisory details multiple vulnerabilities in Newscoop, including Remote File Inclusion (RFI), SQL Injection (SQLi), and Cross-Site Scripting (XSS). It provides Proof-of-Concept (PoC) URLs for each vulnerability but does not include executable exploit code.