CVE-2005-0411 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.41% — more likely to be exploited than 84% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-02-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| citrusdb | citrusdb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CitrusDB 0.3.6 - Arbitrary Local PHP File Inclusion | 2005-02-15 |
References
→ the Explorer · watch your stack · NVD