CVE-2008-3298

SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
social_enginesocial_engine
𝑥
≤ 2.81
social_enginesocial_engine
1.0
social_enginesocial_engine
1.1
social_enginesocial_engine
1.4
social_enginesocial_engine
1.6
social_enginesocial_engine
1.7
social_enginesocial_engine
1.8
social_enginesocial_engine
2.0
social_enginesocial_engine
2.0:online_beta
social_enginesocial_engine
2.1
social_enginesocial_engine
2.4
social_enginesocial_engine
2.5
social_enginesocial_engine
2.7
𝑥
= Vulnerable software versions