CVE-2009-4693
Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG parameter to (1) en.inc.php, (2) hu.inc.php, (3) no.inc.php, (4) ro.inc.php, and (5) ru.inc.php in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG parameter to (1) en.inc.php, (2) hu.inc.php, (3) no.inc.php, (4) ro.inc.php, and (5) ru.inc.php in language/.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- grafxsoftware/minicwb
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/9204
- http://www.securityfocus.com/bid/35738Exploit
- http://www.vupen.com/english/advisories/2009/1960Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51847
- http://www.exploit-db.com/exploits/9204
- http://www.securityfocus.com/bid/35738Exploit
- http://www.vupen.com/english/advisories/2009/1960Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51847
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.