7.5
CVSSv2

CVE-2008-4529

Published: 09/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote malicious users to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8) MemcachedStore.php, (9) Message.php, (10) Nonce.php, (11) SQLStore.php, (12) SReg.php, (13) TrustRoot.php, and (14) URINorm.php in classes/Auth/OpenID/; and (15) XRDS.php, (16) XRI.php and (17) XRIRes.php in classes/Auth/Yadis/.

Vulnerable Product Search on Vulmon Subscribe to Product

asicms asicms 0.208

Exploits

=========================================================================================== [o] asiCMS alpha 0208 Multiple Remote File Inclusion Vulnerability Software : asiCMS version alpha 0208 Vendor : asicmssourceforgenet/ Download : sourceforgenet/project/showfilesphp?group_id=203457 Autho ...