First published: Thu Sep 08 2005(Updated: )
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2846 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2005-2846, upgrade CMS Made Simple to a version higher than 0.10 where the vulnerability is patched.
CVE-2005-2846 affects CMS Made Simple version 0.10 and earlier.
CVE-2005-2846 can facilitate remote file inclusion attacks that lead to the execution of arbitrary PHP code.
Yes, there have been reported exploits for CVE-2005-2846 that target the vulnerable parameter in the lang.php file.