CVE-2006-4240

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2006
Last modified:
20/07/2017

Description

PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fusionphp:fusion_news:1.0:*:*:*:*:*:*:*
cpe:2.3:a:fusionphp:fusion_news:3.3:*:*:*:*:*:*:*
cpe:2.3:a:fusionphp:fusion_news:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:fusionphp:fusion_news:3.7:*:*:*:*:*:*:*