Back

CVE-2005-1840

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.

Published: Jun 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
phpcms phpcms 1.2.0
phpcms phpcms 1.2.1
phpcms phpcms 1.2.1_p12
phpcms phpcms 1.2.1_pl1

GitHub Security Advisory GHSA-frh2-jr4f-m53f

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.84%

Top 23% most likely to be exploited

Threat Score 20.6 / 100

Data Sources

NVD EPSS GitHub