CVE-2008-7000
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.
- Affected products
- Phpauction
- Phpauction
- = 3.2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.1% (79th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2009-08-18
CVE-2008-7000 at NVD
1 known exploit for CVE-2008-7000
Proof-of-concept code and exploit modules indexed by Sploitus