PoC Index

CVE-2012-1933

MEDIUM 6.8EPSS 5.6%

Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3) conf/liveuser_configuration.php.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
5.63% chance of exploitation in the next 30 days, 92th percentile
Published
2012-08-27
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related