Back

CVE-2005-4174

eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.

Published: Dec 11, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-92v9-v65f-f4q8

eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.96%

Top 21% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub