6.8
CVSSv2

CVE-2008-1776

Published: 14/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote malicious users to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpblock phpblock a8.4

Exploits

Script Name : PHP Block a84 Download : sourceforgenet/project/downloadingphp?group_id=186381&use_mirror=surfnet&filename=a84zip&73507325 Error : include_once $PATH_TO_CODE"/script/fonctionphp"; Vul Code : [site]/[Path]/modules/basicfog/basicfogfactoryclassphp?PATH_TO_CODE=[ShellCode] Greetz : Kezzap ...