PoC Index

CVE-2008-5210

HIGH 9.3EPSS 2.8%

Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4) modules/dungeon/tick/allincludefortick.php, different vectors than CVE-2008-1776.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
2.78% chance of exploitation in the next 30 days, 85th percentile
Published
2008-11-24
Updated
2024-08-07

ExploitDB entries (1)

References

Related