CVE-2005-2782

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/09/2005
Last modified:
11/07/2017

Description

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autolinks:autolinks:2.1:*:pro:*:*:*:*:*