CVE-2009-0677
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the…
Does this matter?
Lower severity and a low EPSS score (9.03%). Track it; it rarely justifies an emergency change on its own.
Description
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 9.03% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ravenphpscripts/ravennuke
- Source
- cve@mitre.org
References
- http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7badVendor Advisory
- http://secunia.com/advisories/33928Vendor Advisory
- http://www.osvdb.org/52007
- http://www.securityfocus.com/archive/1/500988/100/0/threaded
- http://www.securityfocus.com/bid/33787
- http://www.waraxe.us/advisory-72.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48789
- https://www.exploit-db.com/exploits/8068
- http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7badVendor Advisory
- http://secunia.com/advisories/33928Vendor Advisory
- http://www.osvdb.org/52007
- http://www.securityfocus.com/archive/1/500988/100/0/threaded
- http://www.securityfocus.com/bid/33787
- http://www.waraxe.us/advisory-72.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48789
- https://www.exploit-db.com/exploits/8068
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.