PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.
References
Configurations
History
No history.
Information
Published : 2006-03-01 02:02
Updated : 2018-10-18 16:29
NVD link : CVE-2006-0945
Mitre link : CVE-2006-0945
CVE.ORG link : CVE-2006-0945
JSON object : View
Products Affected
archangelmgt
- weblog
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')