10
CVSSv2

CVE-2008-5060

Published: 13/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and previous versions allow remote malicious users to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.

Vulnerable Product Search on Vulmon Subscribe to Product

modernbill modernbill 2.01

modernbill modernbill 2.02s

modernbill modernbill 4.1.1

modernbill modernbill 4.1.2

modernbill modernbill 4.1.3

modernbill modernbill 4.0.2

modernbill modernbill 3.1.3

modernbill modernbill

modernbill modernbill 3.0

modernbill modernbill 3.1.0

modernbill modernbill 4.2.1

modernbill modernbill 4.3.0

modernbill modernbill 4.0.1

modernbill modernbill 4.3.2

Exploits

************************************************************************************** ModernBill : Client Billing System - User Login ModernBill <= v44X Remote File Inclusion Vulnerability and xss by nigh7f411 xc0r3net/ plezz go to ttp://xc0r3net/forums/ **************************************************************************** ...