Description
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-2633 | Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T09:05:30.277Z
Reserved: 2008-06-09T00:00:00.000Z
Link: CVE-2008-2638
No data.
Status : Deferred
Published: 2008-06-10T00:32:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-2638
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD