Back

CVE-2005-0679

PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. NOTE: it was later reported that 2.4 is also affected.

Published: May 2, 2005 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
stadtaus tell_a_friend_script *

GitHub Security Advisory GHSA-8qfw-jqf8-hx6m

PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.92%

Top 22% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub