Vulnerabilities > CVE-2005-2782 - Unspecified vulnerability in Autolinks 2.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | AutoLinks 2.1 Pro Al_initialize.PHP Remote File Include Vulnerability. CVE-2005-2782. Webapps exploit for php platform |
id | EDB-ID:26208 |
last seen | 2016-02-03 |
modified | 2005-08-29 |
published | 2005-08-29 |
reporter | 4Degrees |
source | https://www.exploit-db.com/download/26208/ |
title | AutoLinks 2.1 Pro Al_initialize.PHP Remote File Include Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | AUTOLINKS_ALPATH_FILE_INCLUDE.NASL |
description | The remote host is running AutoLinks Pro, a commercial link management package. The version of AutoLinks Pro installed on the remote host allows attackers to control the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19522 |
published | 2005-08-29 |
reporter | This script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/19522 |
title | AutoLinks Pro 'al_initialize.php alpath Parameter Remote File Inclusion |
code |
|
References
- http://marc.info/?l=bugtraq&m=112535379716486&w=2
- http://marc.info/?l=bugtraq&m=112535379716486&w=2
- http://secunia.com/advisories/16620/
- http://secunia.com/advisories/16620/
- http://www.securityfocus.com/bid/14686
- http://www.securityfocus.com/bid/14686
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22061