9
CVSSv2

CVE-2008-4645

Published: 22/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and previous versions allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

Vulnerable Product Search on Vulmon Subscribe to Product

phpwebgallery phpwebgallery 1.4.1

phpwebgallery phpwebgallery 1.1

phpwebgallery phpwebgallery 1.5.0

phpwebgallery phpwebgallery 1.6.0

phpwebgallery phpwebgallery 1.6.2

phpwebgallery phpwebgallery 1.3.4

phpwebgallery phpwebgallery 1.6.1

phpwebgallery phpwebgallery 1.3.2

phpwebgallery phpwebgallery 1.3.3

phpwebgallery phpwebgallery 1.5.2

phpwebgallery phpwebgallery 1.5.1

phpwebgallery phpwebgallery 1.3.0

phpwebgallery phpwebgallery 1.4.0

phpwebgallery phpwebgallery 1.7.0

phpwebgallery phpwebgallery 1.0

phpwebgallery phpwebgallery 1.2.1

phpwebgallery phpwebgallery 1.3.1

phpwebgallery phpwebgallery

phpwebgallery phpwebgallery 1.7.1

Exploits

<?php /* ------------------------------------------------------------------------ PhpWebGallery <= 172 Remote Session Hijacking / Code Execution Exploit ------------------------------------------------------------------------ author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwphpwebgallerynet/ details: ...