CVE-2004-1419
CVE-2004-1419
PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030224.htmlhttp://marc.info/?l=bugtraq&m=110391024404947&w=2http://secunia.com/advisories/13649http://securitytracker.com/id?1012677https://exchange.xforce.ibmcloud.com/vulnerabilities/18677https://exchange.xforce.ibmcloud.com/vulnerabilities/18679http://www.osvdb.org/12580http://www.osvdb.org/12581http://www.securityfocus.com/bid/12103