7.5
CVSSv2

CVE-2008-0433

Published: 23/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.

Vulnerable Product Search on Vulmon Subscribe to Product

agares media phpautovideo

Exploits

source: wwwsecurityfocuscom/bid/27346/info phpAutoVideo is prone to a cross-site scripting vulnerability and a remote file-include vulnerability because it fails to properly sanitize user-supplied input Attackers can exploit these issues to execute arbitrary code within the context of the webserver process, steal cookie-based authentica ...