SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-1068

Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) Vert/index.php, (2) Noir/index.php, and (3) Bleu/index.php in…

MEDIUM 6.8EPSS 1.84%

Does this matter?

Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) Vert/index.php, (2) Noir/index.php, and (3) Bleu/index.php in template/, different vectors than CVE-2008-0645.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.84% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
portail web php/portail web php
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.