CVE-2005-0828
Last modified
CVE-2005-0828 is a vulnerability of currently unknown severity. highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.. EPSS estimates a 9.18% chance of exploitation in the next 30 days.
Description
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ciamos | Ciamos | 0.9.2_rc1 |
| E-Xoops | E-Xoops | 1.05r3 |
| Runcms | Runcms | 1.1a |
References
- http://secunia.com/advisories/14641Patch, Vendor Advisory
- http://secunia.com/advisories/14648Vendor Advisory
- http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txtExploit, URL Repurposed
- http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdfVendor Advisory, URL Repurposed
- http://secunia.com/advisories/14641Patch, Vendor Advisory
- http://secunia.com/advisories/14648Vendor Advisory
- http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txtExploit, URL Repurposed
- http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdfVendor Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0828?
How severe is CVE-2005-0828?
How do I fix CVE-2005-0828?
Are you affected by CVE-2005-0828?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
