7.5
CVSSv2

CVE-2008-5920

Published: 21/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The create_anchors function in utils.inc in WebSVN 1.x allows remote malicious users to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch.

Vulnerable Product Search on Vulmon Subscribe to Product

tigris websvn 1.37

tigris websvn 1.34

tigris websvn 1.03

tigris websvn 1.02

tigris websvn 1.60

tigris websvn 1.61

tigris websvn 1.33

tigris websvn 1.32

tigris websvn 1.01

tigris websvn 1.00

tigris websvn 1.62

tigris websvn 1.51

tigris websvn 1.31a

tigris websvn 1.20

tigris websvn 1.40

tigris websvn 1.39

tigris websvn 1.38

tigris websvn 1.10

tigris websvn 1.04

Exploits

WebSVN <= 20 Multiple Vulnerabilities October 20, 2008 Vendor : Tim Armes URL : websvntigrisorg Version : WebSVN <= 20 Risk : Multiple Vulnerabilities Description: WebSVN is an online SVN repository viewer The description taken from the project website reads "WebSVN offers a view onto your subversion repositories that's b ...