Nessus Plugin #12021

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Remote Code Execution in ezContents

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2004 Noam Rathaus
Summary:
Detect ezContents Code Execution
Version:
$Revision: 1.3 $
Cve_id:
-
Bugtraq_id:
9396
Xrefs:
-
Description:

ezContents is an Open-Source website content management system based
on PHP and MySQL. Features include maintaining menus and sub-menus,
adding authors that write contents, permissions, workflow, and
layout possibilities for the entire look of the site by simple use of settings.

The product has been found to contain a vulnerability that would allow
a remote attacker to cause the PHP script to include an external PHP
file and execute its content. This would allow an attacker to cause
the server to execute arbitrary code.

Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.