CVE-2008-4645

EUVD-2008-4625
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
phpwebgalleryphpwebgallery
𝑥
≤ 1.7.2
phpwebgalleryphpwebgallery
1.0
phpwebgalleryphpwebgallery
1.1
phpwebgalleryphpwebgallery
1.2.1
phpwebgalleryphpwebgallery
1.3.0
phpwebgalleryphpwebgallery
1.3.1
phpwebgalleryphpwebgallery
1.3.2
phpwebgalleryphpwebgallery
1.3.3
phpwebgalleryphpwebgallery
1.3.4
phpwebgalleryphpwebgallery
1.4.0
phpwebgalleryphpwebgallery
1.4.1
phpwebgalleryphpwebgallery
1.5.0
phpwebgalleryphpwebgallery
1.5.1
phpwebgalleryphpwebgallery
1.5.2
phpwebgalleryphpwebgallery
1.6.0
phpwebgalleryphpwebgallery
1.6.1
phpwebgalleryphpwebgallery
1.6.2
phpwebgalleryphpwebgallery
1.7.0
phpwebgalleryphpwebgallery
1.7.1
𝑥
= Vulnerable software versions