Vulnerability Description
PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mansion Productions | Member Area System | <= 1.7 |
Related Weaknesses (CWE)
References
- http://securityreason.com/securityalert/3547
- http://www.securityfocus.com/archive/1/486172/100/0/threaded
- http://www.securityfocus.com/archive/1/486618/100/0/threaded
- http://www.securityfocus.com/bid/27244
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39611
- http://securityreason.com/securityalert/3547
- http://www.securityfocus.com/archive/1/486172/100/0/threaded
- http://www.securityfocus.com/archive/1/486618/100/0/threaded
- http://www.securityfocus.com/bid/27244
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39611
FAQ
What is CVE-2008-0289?
CVE-2008-0289 is a vulnerability with a CVSS score of 6.8 (MEDIUM). PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: ...
How severe is CVE-2008-0289?
CVE-2008-0289 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0289?
Check the references section above for vendor advisories and patch information. Affected products include: Mansion Productions Member Area System.