Back

CVE-2005-2198

PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.

Published: Jul 11, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (9)

Vendor Product Version
spid spid 1.0.1
spid spid 1.0.3
spid spid 1.0.4
spid spid 1.1.0
spid spid 1.2.0
spid spid 1.2.1
spid spid 1.2.2
spid spid 1.2.3
spid spid 1.3.0

GitHub Security Advisory GHSA-4c5m-hq9w-97xw

PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.28%

Top 13% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub