Unrated severityNVD Advisory· Published Nov 6, 2005· Updated Apr 16, 2026
CVE-2005-3519
CVE-2005-3519
Description
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter in (4) Socket.php, (5) Request.php, (6) Mail.php, (7) Date.php, (8) Span.php, (9) mimeDecode.php, and (10) mime.php.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- secunia.com/advisories/16946/nvdExploitPatchVendor Advisory
- securitytracker.com/idnvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/15133/discussnvdExploitPatch
- marc.infonvd
- securityreason.com/securityalert/92nvd
- www.osvdb.org/20035nvd
- www.osvdb.org/20036nvd
- www.osvdb.org/20037nvd
- www.osvdb.org/20038nvd
- www.osvdb.org/20039nvd
- www.osvdb.org/20040nvd
- www.osvdb.org/20041nvd
- www.osvdb.org/20042nvd
- www.osvdb.org/20043nvd
- www.vupen.com/english/advisories/2005/2132nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/22772nvd
News mentions
0No linked articles in our index yet.