Unrated severityNVD Advisory· Published May 2, 2005· Updated Jun 16, 2026
CVE-2005-0828
CVE-2005-0828
Description
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:ciamos:ciamos:0.9.2_rc1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ciamos:ciamos:0.9.2_rc1:*:*:*:*:*:*:*
- (no CPE)range: =0.9.2 RC1
Patches
Vulnerability mechanics
References
10- secunia.com/advisories/14641nvdPatchVendor Advisory
- www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txtnvdExploitURL Repurposed
- www.securityfocus.com/bid/12848nvdExploit
- secunia.com/advisories/14648nvdVendor Advisory
- www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdfnvdVendor AdvisoryURL Repurposed
- marc.infonvd
- marc.infonvd
- securitytracker.com/idnvd
- www.osvdb.org/14890nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19754nvd
News mentions
0No linked articles in our index yet.