Back

CVE-2004-1796

PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
hotnews hotnews 0.5.3
hotnews hotnews 0.6.0
hotnews hotnews 0.6.0_pre
hotnews hotnews 0.6.1
hotnews hotnews 0.7.0
hotnews hotnews 0.7.1
hotnews hotnews 0.7.2

GitHub Security Advisory GHSA-rphj-cr7q-54vg

PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 9.33%

Top 5% most likely to be exploited

Threat Score 32.8 / 100

Data Sources

NVD EPSS GitHub