SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-0828

highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated…

MEDIUM 5.0EPSS 9.18%

Does this matter?

Lower severity and a low EPSS score (9.18%). Track it; it rarely justifies an emergency change on its own.

Description

highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
9.18% probability · 95th percentile
CISA KEV
Not listed
Affected
ciamos/ciamos · e-xoops/e-xoops · runcms/runcms
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.