CVE-2005-4135
N/A
N/A
Summary
Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://securitytracker.com/id?1015323
- http://www.securityfocus.com/archive/1/418838/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2807
- http://www.securityfocus.com/bid/15764
- http://secunia.com/advisories/17949
References
- http://securitytracker.com/id?1015323
- http://www.securityfocus.com/archive/1/418838/100/0/threaded
- http://www.vupen.com/english/advisories/2005/2807
- http://www.securityfocus.com/bid/15764
- http://secunia.com/advisories/17949
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.