Back

CVE-2004-2601

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
ubertec help_center_live 1.2.6

GitHub Security Advisory GHSA-66jf-hpv3-xqhq

PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.45%

Top 29% most likely to be exploited

Threat Score 26 / 100

Data Sources

NVD EPSS GitHub