CVE-2008-2638
HIGH 10.0EPSS 3.9%
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 3.86% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2008-06-10
- Updated
- 2024-08-07