CVE Database
/

CVE-2012-5231

Back to search

CVE-2012-5231

Published: Oct 1, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.

VendorProductVersions

n/a

n/a

affected
n/a

References

18410
exploit
x_refsource_EXPLOIT-DB
51612
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now