VULNERABILITY INTELLIGENCE

CVE-2005-2014

CVSS score4.6 MEDIUM
EPSS probability0.65%
CISA KEVNot currently listed
Published2005-06-20
Last modified2026-06-16

Description

The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.