7.5
CVSSv2

CVE-2005-1222

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

cat_for_gen.php in Annuaire Netref 4.2 allows remote malicious users to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.

Vulnerable Product Search on Vulmon Subscribe to Product

netref netref 4.2

Exploits

source: wwwsecurityfocuscom/bid/13275/info A remote PHP script injection vulnerability affects Netref This issue is due to a failure of the application to sanitize user-supplied data An attacker may leverage this issue to execute arbitrary PHP script code in the context of an affected Web server This will facilitate a compromise of th ...