Back

CVE-2005-2782

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

Published: Sep 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
autolinks autolinks 2.1

GitHub Security Advisory GHSA-3wm9-x999-hch2

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.67%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub