First published: Tue Aug 16 2005(Updated: )
xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | =1.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2574 is classified as a high severity vulnerability due to its potential to allow remote code execution by modifying server variables.
To fix CVE-2005-2574, upgrade XMB Forum to a version newer than 1.9.1 that addresses the variable extraction issue.
CVE-2005-2574 affects users of XMB Forum version 1.9.1 specifically.
CVE-2005-2574 can allow remote attackers to gain unauthorized access or control over server variables, compromising system security.
While CVE-2005-2574 is older, systems running the vulnerable version remain at risk if not updated.