Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
References
Configurations
History
21 Nov 2024, 00:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://1scripts.net/php-scripts/index.php?p=16 - | |
References | () http://secunia.com/advisories/30146 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2008/1735/references - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/42854 - | |
References | () https://www.exploit-db.com/exploits/5736 - |
Information
Published : 2008-06-10 00:32
Updated : 2024-11-21 00:47
NVD link : CVE-2008-2638
Mitre link : CVE-2008-2638
CVE.ORG link : CVE-2008-2638
JSON object : View
Products Affected
1-script
- 1-book
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')