CVE-2009-0517
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 55.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 55.02% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- phpslash/phpslash
- Source
- cve@mitre.org
References
- http://osvdb.org/51727
- http://secunia.com/advisories/33717Vendor Advisory
- http://www.securityfocus.com/archive/1/500664/100/0/threaded
- http://www.securityfocus.com/bid/33572Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48441
- https://www.exploit-db.com/exploits/7948
- http://osvdb.org/51727
- http://secunia.com/advisories/33717Vendor Advisory
- http://www.securityfocus.com/archive/1/500664/100/0/threaded
- http://www.securityfocus.com/bid/33572Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48441
- https://www.exploit-db.com/exploits/7948
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.