peter bassill · operator
$ cve CVE-2005-0980 JSON

CVE-2005-0980 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.68% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
alstrasoftepay

Public exploits

SourceTitleDate
exploit-dbAlstrasoft EPay Pro 2.0 - Remote File Inclusion2005-04-01

References

→ the Explorer  ·  watch your stack  ·  NVD