Back
CVE-2005-2846
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execute arbitrary PHP code via the nls[file][vx][vxsfx] parameter.
Published: Sep 8, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| cmsmadesimple | cms_made_simple | 0.10 |
GitHub Security Advisory GHSA-mq8m-22xh-h584
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows...
References (8)
- http://forum.cmsmadesimple.org/index.php/topic%2C1549.0.html
- http://marc.info/?l=bugtraq&m=112552342004406&w=2
- http://secunia.com/advisories/16654/ Patch, Vendor Advisory
- http://www.securityfocus.com/bid/14709 Exploit
- http://forum.cmsmadesimple.org/index.php/topic%2C1549.0.html
- http://marc.info/?l=bugtraq&m=112552342004406&w=2
- http://secunia.com/advisories/16654/ Patch, Vendor Advisory
- http://www.securityfocus.com/bid/14709 Exploit
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
6.81%
Top 7% most likely to be exploited
Threat Score
32 / 100
Data Sources
NVD
EPSS
GitHub