Back
CVE-2005-0887
Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.
Published: Mar 24, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| michael_dean | double_choco_latte | 0.9.3 |
| michael_dean | double_choco_latte | 0.9.4 |
| michael_dean | double_choco_latte | 0.9.4.2 |
| michael_dean | double_choco_latte | 0.9.4.3 |
GitHub Security Advisory GHSA-5wj3-8v9f-vjph
Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to...
References (8)
- http://secunia.com/advisories/14688 Patch, Vendor Advisory
- http://securitytracker.com/id?1013559 Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=315144 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19806
- http://secunia.com/advisories/14688 Patch, Vendor Advisory
- http://securitytracker.com/id?1013559 Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=315144 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19806
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.74%
Top 15% most likely to be exploited
Threat Score
30.8 / 100
Data Sources
NVD
EPSS
GitHub