Remote Code Execution in Mafia Blog .4 BETA via Admin Directory Vulnerability

Remote Code Execution in Mafia Blog .4 BETA via Admin Directory Vulnerability

CVE-2005-1169 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.

Learn more about our Web Application Penetration Testing UK.