Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
References
Configurations
Information
Published : 2008-06-09 17:32
Updated : 2017-09-28 18:31
NVD link : CVE-2008-2638
Mitre link : CVE-2008-2638
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
1-script
- 1-book