PoC Index

CVE-2008-2638

HIGH 10.0EPSS 3.9%

Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
3.86% chance of exploitation in the next 30 days, 89th percentile
Published
2008-06-10
Updated
2024-08-07

ExploitDB entries (1)

References

Related