Vulnerability Description
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpwebgallery | Phpwebgallery | <= 1.7.2 |
Related Weaknesses (CWE)
References
- http://securityreason.com/securityalert/4456
- http://www.securityfocus.com/bid/31762Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45875
- https://www.exploit-db.com/exploits/6755
- http://securityreason.com/securityalert/4456
- http://www.securityfocus.com/bid/31762Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45875
- https://www.exploit-db.com/exploits/6755
FAQ
What is CVE-2008-4645?
CVE-2008-4645 is a vulnerability with a CVSS score of 9.0 (HIGH). plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is proces...
How severe is CVE-2008-4645?
CVE-2008-4645 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4645?
Check the references section above for vendor advisories and patch information. Affected products include: Phpwebgallery Phpwebgallery.