5
CVSSv2

CVE-2005-0828

Published: 02/05/2005 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote malicious users to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

runcms runcms 1.1a

e-xoops e-xoops 1.05r3

ciamos ciamos 0.9.2_rc1

Exploits

source: wwwsecurityfocuscom/bid/12848/info RunCMS is reportedly affected by an information disclosure vulnerability This issue is due to a failure in the application to secure sensitive information Exploitation of this vulnerability could lead to the disclosure of database configuration details, including the database name, user name a ...