CVE-2003-1292

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2003
Last modified:
03/04/2025

Description

PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ashwebstudio:ashnews:0.83:*:*:*:*:*:*:*