CVE Vulnerabilities

CVE-2005-2782

Published: Sep 02, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for http and https URLs.

Affected Software

Name Vendor Start Version End Version
Autolinks Autolinks 2.1 (including) 2.1 (including)

References