Vulnerability Description
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ftrsoft | Fast Click Sql Lite | 1.1.7 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/32328Vendor Advisory
- http://securityreason.com/securityalert/4454
- http://www.securityfocus.com/bid/31817Exploit
- http://www.vupen.com/english/advisories/2008/2861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45964
- https://www.exploit-db.com/exploits/6785
- http://secunia.com/advisories/32328Vendor Advisory
- http://securityreason.com/securityalert/4454
- http://www.securityfocus.com/bid/31817Exploit
- http://www.vupen.com/english/advisories/2008/2861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45964
- https://www.exploit-db.com/exploits/6785
FAQ
What is CVE-2008-4624?
CVE-2008-4624 is a vulnerability with a CVSS score of 9.3 (HIGH). PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] par...
How severe is CVE-2008-4624?
CVE-2008-4624 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4624?
Check the references section above for vendor advisories and patch information. Affected products include: Ftrsoft Fast Click Sql Lite.