7.5
CVSSv2

CVE-2005-2782

Published: 02/09/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote malicious users to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

Vulnerable Product Search on Vulmon Subscribe to Product

autolinks autolinks 2.1

Exploits

source: wwwsecurityfocuscom/bid/14686/info AutoLinks Pro is prone to a remote file include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web serve ...