CVE-2009-0517
HIGH 10.0EPSS 55.0%
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 55.02% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2009-02-11
- Updated
- 2024-08-07