Search 202850 CVE descriptions
and 87302 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:CGI abuses
Title:BLnews code injection

It is possible to make the remote host include php files hosted
on a third party server using the BLnews CGI suite which is installed.

An attacker may use this flaw to inject arbitrary code in the remote
host and gain a shell with the privileges of the web server.

Solution : Upgrade to the latest version
Risk factor : High

Cross-Ref: BugTraq ID: 7677
Common Vulnerability Exposure (CVE) ID: CVE-2003-0394
Bugtraq: 20030524 PHP source code injection in BLNews (Google Search)
CopyrightThis script is Copyright (C) 2003 Tenable Network Security

This is only one of 87302 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.