CVE
- Id
- 11853
- CVE No.
- CVE-2005-0647
- Status
- Candidate
- Description
- admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.
- Phase
- Assigned (20050304)
- Votes
- None (candidate not yet proposed)
- Comments