Back
CVE-2005-0897
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| magicscripts | e-store_kit-2 | paypal |
GitHub Security Advisory GHSA-jxf3-2j6q-9wgq
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows...
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.46%
Top 29% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub