CVE-2008-4645
22.10.2008, 00:11
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Vendor | Product | Version |
---|---|---|
phpwebgallery | phpwebgallery | 𝑥 ≤ 1.7.2 |
phpwebgallery | phpwebgallery | 1.0 |
phpwebgallery | phpwebgallery | 1.1 |
phpwebgallery | phpwebgallery | 1.2.1 |
phpwebgallery | phpwebgallery | 1.3.0 |
phpwebgallery | phpwebgallery | 1.3.1 |
phpwebgallery | phpwebgallery | 1.3.2 |
phpwebgallery | phpwebgallery | 1.3.3 |
phpwebgallery | phpwebgallery | 1.3.4 |
phpwebgallery | phpwebgallery | 1.4.0 |
phpwebgallery | phpwebgallery | 1.4.1 |
phpwebgallery | phpwebgallery | 1.5.0 |
phpwebgallery | phpwebgallery | 1.5.1 |
phpwebgallery | phpwebgallery | 1.5.2 |
phpwebgallery | phpwebgallery | 1.6.0 |
phpwebgallery | phpwebgallery | 1.6.1 |
phpwebgallery | phpwebgallery | 1.6.2 |
phpwebgallery | phpwebgallery | 1.7.0 |
phpwebgallery | phpwebgallery | 1.7.1 |
𝑥
= Vulnerable software versions
References