nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2003-08/0345.html | Exploit Vendor Advisory |
Configurations
Information
Published : 2003-10-19 21:00
Updated : 2008-09-10 12:20
NVD link : CVE-2003-0753
Mitre link : CVE-2003-0753
JSON object : View
CWE
Products Affected
newsphp
- newsphp