PoC Index

CVE-2005-3571

MEDIUM 5.0EPSS 3.5%

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.49% chance of exploitation in the next 30 days, 88th percentile
Published
2005-11-16
Updated
2024-08-07

ExploitDB entries (1)

References

Related