PoC Index

CVE-2008-2981

MEDIUM 6.8EPSS 1.7%

PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the thumb_template parameter.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.69% chance of exploitation in the next 30 days, 75th percentile
Published
2008-07-02
Updated
2024-08-07

ExploitDB entries (1)

References

Related