CVE-2008-6482
medium · 6.8PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.
6.8
CVSS
22.1%
EPSS (exploit prob.)
98th
EPSS percentile
2009-03-18
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| justjoomla | com_treeg | 1.0 |
| joomla | joomla | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/49499
- http://secunia.com/advisories/32520
- http://www.securityfocus.com/bid/32041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46260
- https://www.exploit-db.com/exploits/6928
- http://osvdb.org/49499
- http://secunia.com/advisories/32520
- http://www.securityfocus.com/bid/32041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46260
- https://www.exploit-db.com/exploits/6928
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-6482