CVE-2008-2638
N/A
N/A
Summary
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.exploit-db.com/exploits/5736
- http://secunia.com/advisories/30146
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42854
- http://www.vupen.com/english/advisories/2008/1735/references
- http://1scripts.net/php-scripts/index.php?p=16
References
- https://www.exploit-db.com/exploits/5736
- http://secunia.com/advisories/30146
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42854
- http://www.vupen.com/english/advisories/2008/1735/references
- http://1scripts.net/php-scripts/index.php?p=16
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.