Unrated severityNVD Advisory· Published Sep 9, 2006· Updated Apr 16, 2026
CVE-2006-4666
CVE-2006-4666
Description
Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.
Affected products
1- cpe:2.3:a:stefan_ernst:newsscript:0.5:beta:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/19886nvdExploit
- www.vupen.com/english/advisories/2006/3558nvdVendor Advisory
- secunia.com/advisories/21826nvd
- securityreason.com/securityalert/1533nvd
- securitytracker.com/idnvd
- www.osvdb.org/28813nvd
- www.securityfocus.com/archive/1/445523/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28813nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28892nvd
News mentions
0No linked articles in our index yet.