CVE-2005-0859

UnknownEPSS 11.40%

Last modified

CVE-2005-0859 is a vulnerability of currently unknown severity. PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. EPSS estimates a 11.40% chance of exploitation in the next 30 days.

Description

PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

Metrics

EPSS Probability
11.40%

95.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Czaries NetworkCzarnews1.13b

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-0859?
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.
How severe is CVE-2005-0859?
Severity scoring for CVE-2005-0859 is pending analysis. The EPSS model estimates a 11.40% probability of exploitation in the next 30 days.
How do I fix CVE-2005-0859?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-0859?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST