RULE(RULE ID:322342)

Rule General Information
Release Date: 2019-07-05
Rule Name: WMNews index.php base_datapath Parameter PHP File Include Vulnerability (CVE-2006-3928)
Severity:
CVE ID:
Rule Protection Details
Description: PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_datapath parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:19187
ExploitDB:2077
http://www.vupen.com/english/advisories/2006/3013
https://exchange.xforce.ibmcloud.com/vulnerabilities/28029
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://wartamikael.org/PHPScripts/