10
CVE-2008-2638
- EPSS 3.86%
- Veröffentlicht 10.06.2008 00:32:00
- Zuletzt bearbeitet 16.06.2026 22:54:08
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.86% | 0.888 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
http://1scripts.net/php-scripts/index.php?p=16
http://secunia.com/advisories/30146
http://www.vupen.com/english/advisories/2008/1735/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42854
https://www.exploit-db.com/exploits/5736