CVE-2008-4329

EUVD-2008-4310
PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
openengineopenengine
𝑥
≤ 2.0_beta4
openengineopenengine
1.7.1
openengineopenengine
1.8_beta2:_beta2
openengineopenengine
1.9_beta1:_beta1
openengineopenengine
1.9_beta2:_beta2
openengineopenengine
1.9_beta3:_beta3
𝑥
= Vulnerable software versions