10
CVSSv2

CVE-2008-2638

Published: 10/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and previous versions allows remote malicious users to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.

Vulnerable Product Search on Vulmon Subscribe to Product

1-script 1-book

Exploits

========================================================= =============== JIKI TEAM [ Maroc And YameN ]=============== ========================================================= # Author : jiko # email : jalikom@hotmailfr # Home : wwwno-backorg & no-exploitcom # Script : 1Book Guestbook Script # Bug : remote code execution # Download ...