VYPR
Unrated severityNVD Advisory· Published Nov 23, 2004· Updated Apr 16, 2026

CVE-2004-0246

CVE-2004-0246

Description

Les Commentaires 2.0 contains multiple PHP remote file inclusion vulnerabilities via the rep parameter in three scripts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Les Commentaires 2.0 contains multiple PHP remote file inclusion vulnerabilities via the rep parameter in three scripts.

Vulnerability

Les Commentaires 2.0 is prone to multiple remote file inclusion vulnerabilities in files fonctions.lib.php, derniers_commentaires.php, and admin.php. The rep parameter is not properly sanitized, allowing an attacker to specify a remote URL that is included and executed by PHP. This affects version 2.0 of the software [1].

Exploitation

An attacker can exploit this by sending a crafted HTTP request to any of the three vulnerable scripts, providing a malicious URL in the rep parameter. The attacker does not need authentication, as these scripts are accessible from the web root. The only requirement is network access to the web server hosting Les Commentaires [1].

Impact

Successful exploitation allows the attacker to execute arbitrary PHP code on the target server in the context of the web server user. This can lead to full compromise of the web application and potentially the underlying system, including data theft, defacement, or further attacks [1].

Mitigation

No official patch or fixed version is detailed in the available references. Users should upgrade to a later version if available, or remove or restrict access to the affected scripts. The advisory does not list this CVE as part of the CISA KEV [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:laurent_adda:les_commentaires:2.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:laurent_adda:les_commentaires:2.0:*:*:*:*:*:*:*
    • (no CPE)range: = 2.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.