10
CVSSv2

CVE-2008-4329

Published: 30/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the oe_classpath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

openengine openengine 1.9_beta2

openengine openengine 1.9_beta3

openengine openengine 1.7.1

openengine openengine 1.8_beta2

openengine openengine 1.9_beta1

openengine openengine

Exploits

:::::::- :::::: ::: ;;, `';, ;; ;;;`;;;;, `;;; `[[ [[[[' [[[ [[[[[ '[[ $$, $$$$ $$$ $$$ "Y$c$$ 888_,o8P'88 d888 888 Y88 MMMMP"` "YmmMMMM"" MMM YM [ Discovered by dun \ dun[at]strcpypl ] ######################################################################## # [ op ...