CVE-2005-3571
CodeGrrl PHPCalendar/PHPClique/PHPCurrently/PHPFanBase/PHPQuotes Remote File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3571. PoCs published by Robin Verton.
AI-analyzed exploit summary The provided text describes a remote arbitrary code execution vulnerability in unspecified Codegrrl applications due to improper input sanitization. The example URL demonstrates how an attacker could exploit this by injecting a malicious URL via the 'siteurl' parameter.
Description
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.
Exploits (1)
The provided text describes a remote arbitrary code execution vulnerability in unspecified Codegrrl applications due to improper input sanitization. The example URL demonstrates how an attacker could exploit this by injecting a malicious URL via the 'siteurl' parameter.