CVE-2004-0246
Description
Les Commentaires 2.0 contains multiple PHP remote file inclusion vulnerabilities via the rep parameter in three scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Les Commentaires 2.0 contains multiple PHP remote file inclusion vulnerabilities via the rep parameter in three scripts.
Vulnerability
Les Commentaires 2.0 is prone to multiple remote file inclusion vulnerabilities in files fonctions.lib.php, derniers_commentaires.php, and admin.php. The rep parameter is not properly sanitized, allowing an attacker to specify a remote URL that is included and executed by PHP. This affects version 2.0 of the software [1].
Exploitation
An attacker can exploit this by sending a crafted HTTP request to any of the three vulnerable scripts, providing a malicious URL in the rep parameter. The attacker does not need authentication, as these scripts are accessible from the web root. The only requirement is network access to the web server hosting Les Commentaires [1].
Impact
Successful exploitation allows the attacker to execute arbitrary PHP code on the target server in the context of the web server user. This can lead to full compromise of the web application and potentially the underlying system, including data theft, defacement, or further attacks [1].
Mitigation
No official patch or fixed version is detailed in the available references. Users should upgrade to a later version if available, or remove or restrict access to the affected scripts. The advisory does not list this CVE as part of the CISA KEV [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:laurent_adda:les_commentaires:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:laurent_adda:les_commentaires:2.0:*:*:*:*:*:*:*
- (no CPE)range: = 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/9536nvdExploitVendor Advisory
- marc.infonvd
- secunia.com/advisories/10768/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15010nvd
News mentions
0No linked articles in our index yet.