First published: Wed Nov 16 2005(Updated: )
PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3574 is considered to have a high severity due to its potential for remote file inclusion leading to arbitrary code execution.
To fix CVE-2005-3574, ensure that you are using the latest version of iCMS which addresses this vulnerability.
Exploiting CVE-2005-3574 allows attackers to include arbitrary files from the server, which can lead to data leakage or remote code execution.
All versions of iCMS prior to the security patch that addresses CVE-2005-3574 are vulnerable to this issue.
CVE-2005-3574 is primarily a remote vulnerability, allowing external attackers to exploit it if the application is accessible over the internet.