Vulnerabilities > CVE-2005-0828

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
runcms
e-xoops
ciamos
exploit available

Summary

highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

Vulnerable Configurations

Part Description Count
Application
Runcms
1
Application
E-Xoops
1
Application
Ciamos
1

Exploit-Db

descriptionRunCMS 1.1 Database Configuration Information Disclosure Vulnerability. CVE-2005-0828. Webapps exploit for php platform
idEDB-ID:25237
last seen2016-02-03
modified2005-03-18
published2005-03-18
reporterMajid NT
sourcehttps://www.exploit-db.com/download/25237/
titleRunCMS 1.1 Database Configuration Information Disclosure Vulnerability