Vulnerabilities > CVE-2005-0680

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
stadtaus
exploit available

Summary

PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.

Vulnerable Configurations

Part Description Count
Application
Stadtaus
1

Exploit-Db

descriptionDownload Center Lite (DCL) <= 1.5 Remote File Inclusion. CVE-2005-0680. Webapps exploit for php platform
idEDB-ID:870
last seen2016-01-31
modified2005-03-10
published2005-03-10
reporterFilip Groszynski
sourcehttps://www.exploit-db.com/download/870/
titleDownload Center Lite DCL <= 1.5 - Remote File Inclusion