6.8
CVSSv2

CVE-2009-4834

Published: 04/05/2010 Updated: 19/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

lib.php in Zeroboard 4.1 pl7 allows remote malicious users to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xpressengine zeroboard 4.1

Exploits

/* poc by kyoungchip,jang email : SpeeDr00t1004@gmailcom [*] the bug - wwwxpressenginecom/15955761 Application - Zeroboard 41 pl7 Reference: - wwwnzeocom - Zeroboard preg_replace() vulnerability Remote nobody exploit by n0gada [*] Target - My test server $ /zbexpl xxxxxxxxx/zboard/zboardphp?id=test ...