MidnightBSD

Advisories for codegrrl

CVE-2005-3571 MEDIUM

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
codegrrl phpfanbase *
codegrrl phpclique *
codegrrl phpcalendar *
codegrrl phpquotes *
codegrrl phpcurrently *