Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1796
CVE-2004-1796
Description
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.
Affected products
7cpe:2.3:a:hotnews:hotnews:0.5.3:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:hotnews:hotnews:0.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.6.0_pre:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:hotnews:hotnews:0.7.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/10551nvdPatch
- sourceforge.net/forum/forum.phpnvdPatch
- securitytracker.com/idnvdExploitPatch
- www.securityfocus.com/archive/1/348840nvdExploitPatch
- www.securityfocus.com/bid/9357nvdExploitPatch
- www.osvdb.org/3332nvd
- www.osvdb.org/3405nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/14140nvd
News mentions
0No linked articles in our index yet.