CVE-2005-1169 Information

Description

Mafia Blog .4 BETA does not properly protect the admin directory which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.

Reference

http://chrisnowak.org/projects/mafia/ http://marc.info/?l=bugtraq&m=111359511826958&w=2 http://www.securityfocus.com/bid/13194

Share on: