7.5
CVSSv2

CVE-2005-3519

Published: 06/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 795
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote malicious users to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter in (4) Socket.php, (5) Request.php, (6) Mail.php, (7) Date.php, (8) Span.php, (9) mimeDecode.php, and (10) mime.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mysource mysource 2.14.0

mysource mysource 2.14.0rc2

Exploits

source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected com ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected compu ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with t ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer wi ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected compute ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the p ...
source: wwwsecurityfocuscom/bid/15133/info MySource is prone to multiple remote and local file include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer ...