9.3
CVSSv2

CVE-2008-2886

Published: 27/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 up to and including 3.3.5, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jamroom jamroom 3.3.2

jamroom jamroom 3.3.3

jamroom jamroom 3.3.4

jamroom jamroom 3.3.5

jamroom jamroom 3.3.0

jamroom jamroom 3.3.1

Exploits

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Scripts : CMS Jamroom Version: 335 Discovered By : Cyberlog Scripts site : wwwjamroomnet/ Download Script : wwwjamroomnet/indexphp?m=td_download&o=download&file_id=43 Thanks To : #sekuritionline, #semprol, #bajin ...