7.5
CVSSv2

CVE-2004-0285

Published: 23/11/2004 Updated: 23/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote malicious users to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

allmyguests project allmyguests 0.4.1

allmyguests project allmyguests 0.4

allmyguests project allmyguests 0.3

allmyguests project allmyguests 0.1.2

allmylinks project allmylinks 0.3

allmylinks project allmylinks 0.4

allmylinks project allmylinks 0.4.1

allmylinks project allmylinks 0.4.3

allmylinks project allmylinks 0.4.4

allmylinks project allmylinks 0.4.9

allmylinks project allmylinks 0.5

allmyvisitors project allmyvisitors 0.4

allmyvisitors project allmyvisitors 0.3

Exploits

source: wwwsecurityfocuscom/bid/9664/info Reportedly the AllMyPHP application AllMyGuests is prone to a remote file include vulnerability The issue is due to insufficient filtering of URI passed variables that are used in a 'require_once()' call This issue may allow a remote attacker to execute arbitrary commands on the affected system ...
source: wwwsecurityfocuscom/bid/9664/info Reportedly the AllMyPHP applications AllMyGuests, AllMyLinks and AllMyVisitors are prone to a remote file include vulnerability The issue is due to insufficient filtering of URI passed variables that are used in a 'require_once()' call This issue may allow a remote attacker to execute arbit ...
source: wwwsecurityfocuscom/bid/9664/info Reportedly the AllMyPHP applications AllMyGuests, AllMyLinks and AllMyVisitors are prone to a remote file include vulnerability The issue is due to insufficient filtering of URI passed variables that are used in a 'require_once()' call This issue may allow a remote attacker to execute arbitra ...