First published: Tue Mar 22 2005(Updated: )
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ciamos CMS | =0.9.2_rc1 | |
E-xoops | =1.05r3 | |
Runcms Runcms | =1.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0828 has a medium severity level due to its potential for remote file reading exploits.
To fix CVE-2005-0828, ensure that access controls are implemented on sensitive files and upgrade to a patched version of the affected software.
CVE-2005-0828 affects RUNCMS 1.1A, CIAMOS 0.9.2 RC1, and E-xoops 1.05 Rev3.
CVE-2005-0828 is a file inclusion vulnerability that allows attackers to read arbitrary PHP files.
Yes, CVE-2005-0828 can lead to the exposure of sensitive data such as database configuration information.