Lucene search

K
nvd[email protected]NVD:CVE-2009-0643
HistoryFeb 20, 2009 - 6:47 a.m.

CVE-2009-0643

2009-02-2006:47:48
CWE-94
web.nvd.nist.gov
1

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.013

Percentile

85.7%

Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
dminnichsimple_php_newsMatch1.0
VendorProductVersionCPE
dminnichsimple_php_news1.0cpe:2.3:a:dminnich:simple_php_news:1.0:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.013

Percentile

85.7%

Related for NVD:CVE-2009-0643