VULNERABILITY INTELLIGENCE
CVE-2005-2014
CVSS score4.6 MEDIUM
EPSS probability0.65%
CISA KEVNot currently listed
Published2005-06-20
Last modified2026-06-16
Description
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.