CVE-2005-0565: High severity phpWebSite phpWebSite vulnerability
Published Feb 27, 2005
·Updated
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.
Affected Software
10 affected components
phpWebSite phpWebSite=0.9.0
phpWebSite phpWebSite=0.9.1
phpWebSite phpWebSite=0.9.2
phpWebSite phpWebSite=0.9.2.1
phpWebSite phpWebSite=0.9.3
phpWebSite phpWebSite=0.9.3.1
phpWebSite phpWebSite=0.9.3.2
phpWebSite phpWebSite=0.9.3.3
phpWebSite phpWebSite=0.9.3.4
phpWebSite phpWebSite=0.10.0
Remediation
Patch Available
Patch Available
Event History
Feb 27, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0565?
CVE-2005-0565 is classified as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2005-0565?
To fix CVE-2005-0565, upgrade your phpWebSite installation to version 0.10.1 or later.
3
What versions of phpWebSite are affected by CVE-2005-0565?
CVE-2005-0565 affects phpWebSite versions up to and including 0.10.0.
4
Can CVE-2005-0565 be exploited remotely?
Yes, CVE-2005-0565 can be exploited by remote attackers without authentication.
5
What kind of impact does CVE-2005-0565 have on phpWebSite?
CVE-2005-0565 allows remote attackers to execute arbitrary PHP code, compromising the security of the phpWebSite application.