forum.cmsmadesimple.orgConfirmation
http://forum.cmsmadesimple.org/index.php/topic%2C1549.0.html CVE-2005-2846
CMS Made Simple 0.10 - 'Lang.php' Remote File Inclusion
Record summary
CVE-2005-2846 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMS Made Simple 0.10 - 'Lang.php' Remote File InclusionExploitDB exploitby groszynskifNot analyzed1 file
References
6forum.cmsmadesimple.org
http://forum.cmsmadesimple.org/index.php/topic,1549.0.html 20050831 CMS Made Simple <= 0.10 - PHP injectionmailing list
http://marc.info/?l=bugtraq&m=112552342004406&w=2 16654Third-party advisory
http://secunia.com/advisories/16654 14709vdb entry
http://www.securityfocus.com/bid/14709 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2846