CVE-2006-0945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
01/03/2006
Last modified:
18/10/2018

Description

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:archangelmgt:weblog:0.90.02:*:*:*:*:*:*:*