CVE-2006-5100: High severity netwin webnews vulnerability
Published Oct 3, 2006
·Updated
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WNBASEDIR parameter.
Affected Software
5 affected components
Netwin WebNews=1.1h
Netwin WebNews=1.1i
Netwin WebNews=1.1j
Netwin WebNews=1.1k
Netwin WebNews=1.4
Event History
Oct 3, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:03 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5100?
CVE-2006-5100 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-5100?
To fix CVE-2006-5100, upgrade to the latest version of WEB//NEWS that addresses this vulnerability.
3
What software is affected by CVE-2006-5100?
CVE-2006-5100 affects WEB//NEWS versions 1.4 and earlier.
4
Can CVE-2006-5100 be exploited remotely?
Yes, CVE-2006-5100 can be exploited remotely by attackers using a malicious URL.
5
What consequences can occur if CVE-2006-5100 is exploited?
Exploiting CVE-2006-5100 can allow attackers to execute arbitrary PHP code on the vulnerable server.