{ "schema_version": "1.4.0", "id": "GHSA-c58f-48r6-vx5g", "modified": "2022-05-01T02:12:26Z", "published": "2022-05-01T02:12:26Z", "aliases": [ "CVE-2005-2865" ], "details": "Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) directone.inc.php, (7) authorize_aim.inc.php, (8) beanstream.inc.php, (9) config.inc.php, (10) eprocessingnetwork.inc.php, (11) eway.inc.php, (12) linkpoint.inc.php, (13) logiccommerce.inc.php, (14) netbilling.inc.php, (15) payflow_pro.inc.php, (16) paymentsgateway.inc.php, (17) payos.inc.php, (18) payready.inc.php, or (19) plugnplay.inc.php.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2865" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/22157" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=112605375926801&w=2" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2005-09-08T23:03:00Z" } }