9.3
CVSSv2

CVE-2008-6748

Published: 24/04/2009 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Eval injection vulnerability in Megacubo 5.0.7 allows remote malicious users to inject and execute arbitrary PHP code via the play action in a mega:// URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

megacubo megacubo 5.0.7

Exploits

Megacubo 507 download & Execute by :JJunior site: wwwmusicastopcombr/ tested against Internet Explorer 7 and Mozilla Firefox 15 Windows Xp sp 3 software site: wwwmegacubonet/tv/ download url: sourceforgenet/project/showfilesphp?group_id=231636&package_id=280849&release_id=608023 description: "Megacub ...
<!-- Megacubo 507 (mega://) remote eval() injection exploit by Nine:Situations:Group::pyrokinesis site: retrogodaltervistaorg/ tested against Internet Explorer 8 beta 2/xp sp 3 software site: wwwmegacubonet/tv/ download url: sourceforgenet/project/showfilesphp?group_id=231636&package_id=280849&release_id=60 ...