5
CVSSv2

CVE-2005-3571

Published: 16/11/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote malicious users to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

codegrrl phpclique

codegrrl phpfanbase

codegrrl phpquotes

codegrrl phpcalendar

codegrrl phpcurrently

Exploits

source: wwwsecurityfocuscom/bid/15417/info Unspecified Codegrrl applications are prone to a remote arbitrary code execution vulnerability This is due to a lack of proper sanitization of user-supplied input An attacker can exploit this to execute arbitrary code in the context of the Web server process This may facilitate a compromise o ...