Back

CVE-2005-3571

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.

Published: Nov 16, 2005 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (5)

Vendor Product Version
codegrrl phpcalendar *
codegrrl phpclique *
codegrrl phpcurrently *
codegrrl phpfanbase *
codegrrl phpquotes *

GitHub Security Advisory GHSA-663v-cjm7-6hwq

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 3.49%

Top 12% most likely to be exploited

Threat Score 21 / 100

Data Sources

NVD EPSS GitHub