Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-3519

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-3519
Last Modified 07 Mar 2011 09:26:42
Published 06 Nov 2005 06:03:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-3519

Summary

Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter in (4) Socket.php, (5) Request.php, (6) Mail.php, (7) Date.php, (8) Span.php, (9) mimeDecode.php, and (10) mime.php.

Vulnerable Systems

Application

  • Mysource 2.14.0

  • Mysource 2.14.0rc2


References

XF - mysource-multiple-file-include(22772)

BID - 15133

SECTRACK - 1015075

SECUNIA - 16946

BUGTRAQ - 20051018 Secunia Research: MySource Cross-Site Scripting and File Inclusion

VUPEN - ADV-2005-2132

OSVDB - 20043

OSVDB - 20042

OSVDB - 20041

OSVDB - 20040

OSVDB - 20039

OSVDB - 20038

OSVDB - 20037

OSVDB - 20036

OSVDB - 20035

SREASON - 92


Last Updated: 27 May 2016 10:40:57