Back
CVE-2005-2328
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.
Published: Jul 20, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| laffer | laffer | 0.3.2.6 |
| laffer | laffer | 0.3.2.7 |
GitHub Security Advisory GHSA-fj8x-xf49-vwfw
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote...
References (6)
- http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&key=373747410 Patch
- http://sourceforge.net/tracker/index.php?func=detail&aid=1235463&group_id=101249&atid=629313 Exploit
- http://www.securityfocus.com/bid/14264 Patch
- http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&key=373747410 Patch
- http://sourceforge.net/tracker/index.php?func=detail&aid=1235463&group_id=101249&atid=629313 Exploit
- http://www.securityfocus.com/bid/14264 Patch
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
1.40%
Top 30% most likely to be exploited
Threat Score
20.4 / 100
Data Sources
NVD
EPSS
GitHub