Security Advisory

CVE-2006-3685

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-07-18 21:00:00
Last updated 2024-08-07 18:39:53
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.