10
CVSSv2

CVE-2008-2480

Published: 28/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote malicious users to execute arbitrary PHP code via a URL in the _pages_dir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

plusphp plusphp short url multi-user script 1.6

Exploits

Author: DRTOXIC / drtoxic@windowslivecom Title: plusPHP Multi-User Short URL and Statistics (plusphp) RFI Vulnerability Script Download: wwwhotscriptscom/jumpphp?listing_id=80293&jump_type=1 Vulnerability Code: (plusphp) "include ($_pages_dir'_configphp');" Example; localhost/plusphp?_pages_dir=SH3LL? <---- ...