CVE-2008-4645

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
phpwebgalleryphpwebgallery
𝑥
≤ 1.7.2
phpwebgalleryphpwebgallery
1.0
phpwebgalleryphpwebgallery
1.1
phpwebgalleryphpwebgallery
1.2.1
phpwebgalleryphpwebgallery
1.3.0
phpwebgalleryphpwebgallery
1.3.1
phpwebgalleryphpwebgallery
1.3.2
phpwebgalleryphpwebgallery
1.3.3
phpwebgalleryphpwebgallery
1.3.4
phpwebgalleryphpwebgallery
1.4.0
phpwebgalleryphpwebgallery
1.4.1
phpwebgalleryphpwebgallery
1.5.0
phpwebgalleryphpwebgallery
1.5.1
phpwebgalleryphpwebgallery
1.5.2
phpwebgalleryphpwebgallery
1.6.0
phpwebgalleryphpwebgallery
1.6.1
phpwebgalleryphpwebgallery
1.6.2
phpwebgalleryphpwebgallery
1.7.0
phpwebgalleryphpwebgallery
1.7.1
𝑥
= Vulnerable software versions