PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.
References
Configurations
Information
Published : 2006-02-28 18:02
Updated : 2018-10-18 09:29
NVD link : CVE-2006-0945
Mitre link : CVE-2006-0945
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
archangelmgt
- weblog