CVE-2005-0679

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
02/05/2005
Last modified:
03/04/2025

Description

PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. NOTE: it was later reported that 2.4 is also affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stadtaus:tell_a_friend_script:*:*:*:*:*:*:*:* 2.7 (including)