CVE

Id
11853  
CVE No.
CVE-2005-0647  
Status
Candidate  
Description
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.  
Phase
Assigned (20050304)  
Votes
None (candidate not yet proposed)  
Comments