Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-0828
CVE-2005-0828
Description
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/14641nvdPatchVendor Advisory
- www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txtnvdExploitURL Repurposed
- www.securityfocus.com/bid/12848nvdExploit
- secunia.com/advisories/14648nvdVendor Advisory
- www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdfnvdVendor AdvisoryURL Repurposed
- marc.infonvd
- marc.infonvd
- securitytracker.com/idnvd
- www.osvdb.org/14890nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19754nvd
News mentions
0No linked articles in our index yet.