Back
CVE-2004-2010
PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
GitHub Security Advisory GHSA-cmr2-j9xp-h9cf
PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote...
References (10)
- http://marc.info/?l=bugtraq&m=108420702317870&w=2
- http://secunia.com/advisories/11587 Patch
- http://www.fribble.net/advisories/phpshop_29-04-04.txt
- http://www.securityfocus.com/bid/10313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16107
- http://marc.info/?l=bugtraq&m=108420702317870&w=2
- http://secunia.com/advisories/11587 Patch
- http://www.fribble.net/advisories/phpshop_29-04-04.txt
- http://www.securityfocus.com/bid/10313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16107
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.57%
Top 16% most likely to be exploited
Threat Score
30.8 / 100
Data Sources
NVD
EPSS
GitHub