CVE-2005-3571

critical

Description

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

References

http://www.vupen.com/english/advisories/2005/2402

http://www.securityfocus.com/bid/21664

http://www.securityfocus.com/bid/15417

http://securitytracker.com/id?1015206

http://securityreason.com/securityalert/176

http://secunia.com/advisories/17542

http://marc.info/?l=bugtraq&m=113199214723444&w=2

Details

Source: Mitre, NVD

Published: 2005-11-16

Updated: 2016-10-18

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical