CVE-2005-0828 describes a local file inclusion vulnerability in highlight.php, affecting RUNCMS 1.1A, CIAMOS 0.9.2 RC1, e-Xoops 1.05 Rev3, and other e-Xoops-based products. This flaw allows unauthenticated remote attackers to read arbitrary PHP files, such as database configuration information from mainfile.php, by manipulating the 'file' parameter. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it is a medium-severity vulnerability, indicating low attack complexity and a high potential for information disclosure. While not actively exploited in the wild or on the KEV catalog, a public exploit (EDB-25237) exists, and it has a FAUCET Risk Score of 81/100, suggesting a notable risk despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.2_rc1CPE matchmatch criteria | cpe:2.3:a:ciamos:ciamos:0.9.2_rc1:*:*:*:*:*:*:* | ||
1.05r3CPE matchmatch criteria | cpe:2.3:a:e-xoops:e-xoops:1.05r3:*:*:*:*:*:*:* | ||
1.1aCPE matchmatch criteria | cpe:2.3:a:runcms:runcms:1.1a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.