Unrated severityNVD Advisory· Published Aug 22, 2006· Updated Apr 16, 2026
CVE-2006-4285
CVE-2006-4285
Description
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected.
Affected products
4cpe:2.3:a:fscripts:fantastic_news:2.1.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:fscripts:fantastic_news:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:fscripts:fantastic_news:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:fscripts:fantastic_news:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:fscripts:fantastic_news:2.1.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- fscripts.com/index.phpnvdPatch
- secunia.com/advisories/21571nvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/19613nvdExploitPatch
- www.vupen.com/english/advisories/2006/3336nvdVendor Advisory
- www.securityfocus.com/archive/1/457680/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28469nvd
- www.exploit-db.com/exploits/2221nvd
News mentions
0No linked articles in our index yet.