CVE-2009-0517
high · 10Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.
10
CVSS
55.0%
EPSS (exploit prob.)
99th
EPSS percentile
2009-02-11
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| phpslash | phpslash | all versions |
| phpslash | phpslash | <= 0.8.1.1 |
| phpslash | phpslash | 0.5.3.2 |
| phpslash | phpslash | 0.6 |
| phpslash | phpslash | 0.6.1 |
| phpslash | phpslash | 0.6.2 |
| phpslash | phpslash | 0.7.1 |
| phpslash | phpslash | 0.7.2 |
| phpslash | phpslash | 0.8.0 |
| phpslash | phpslash | 0.8.1 |
| phpslash | phpslash | 0.61 |
| phpslash | phpslash | 065 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/51727
- http://secunia.com/advisories/33717
- http://www.securityfocus.com/archive/1/500664/100/0/threaded
- http://www.securityfocus.com/bid/33572
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48441
- https://www.exploit-db.com/exploits/7948
- http://osvdb.org/51727
- http://secunia.com/advisories/33717
- http://www.securityfocus.com/archive/1/500664/100/0/threaded
- http://www.securityfocus.com/bid/33572
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48441
- https://www.exploit-db.com/exploits/7948
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-0517