CVE-2005-3571

N/A Unknown
Published: November 16, 2005 Modified: April 16, 2026
View on NVD

Description

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/17542
Source: cve@mitre.org
Vendor Advisory
http://www.vupen.com/english/advisories/2005/2402
Source: cve@mitre.org
Vendor Advisory
http://marc.info/?l=bugtraq&m=113199214723444&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/17542
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securityreason.com/securityalert/176
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1015206
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/15417
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/21664
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2005/2402
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
9.0%
93th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

codegrrl