10
CVE-2008-6826
- EPSS 4.6%
- Veröffentlicht 08.06.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:03:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.6% | 0.904 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://osvdb.org/49406
http://secunia.com/advisories/32402
http://www.securityfocus.com/bid/31923
https://exchange.xforce.ibmcloud.com/vulnerabilities/46121
https://www.exploit-db.com/exploits/6845