Back
CVE-2004-2601
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| ubertec | help_center_live | 1.2.6 |
GitHub Security Advisory GHSA-66jf-hpv3-xqhq
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers...
References (10)
- http://secunia.com/advisories/13652 Vendor Advisory
- http://securitytracker.com/id?1012685
- http://www.gulftech.org/?node=research&article_id=00058-12242004
- http://www.osvdb.org/12631
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18695
- http://secunia.com/advisories/13652 Vendor Advisory
- http://securitytracker.com/id?1012685
- http://www.gulftech.org/?node=research&article_id=00058-12242004
- http://www.osvdb.org/12631
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18695
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
1.45%
Top 29% most likely to be exploited
Threat Score
26 / 100
Data Sources
NVD
EPSS
GitHub