PoC Index

CVE-2005-0828

MEDIUM 5.0EPSS 9.2%

highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
9.18% chance of exploitation in the next 30 days, 95th percentile
Published
2005-03-22
Updated
2024-08-07

ExploitDB entries (1)

References

Related