Back

CVE-2005-0411

Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.

Published: Feb 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
citrusdb citrusdb *

GitHub Security Advisory GHSA-4rcx-jwpr-7mp7

Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.41%

Top 17% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub