CVE
- Id
- 13988
- CVE No.
- CVE-2005-2782
- Status
- Candidate
- Description
- PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
- Phase
- Assigned (20050902)
- Votes
- None (candidate not yet proposed)
- Comments