5
CVSSv2

CVE-2005-3910

Published: 30/11/2005 Updated: 09/10/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

merchants/index.php in Post Affiliate Pro 2.0.4 and previous versions, with magic_quotes_gpc disabled, allows remote malicious users to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

post affiliate pro post affiliate pro 2.0.4