CVE-2008-5071

Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
yoxelyoxel
𝑥
≤ 1.23beta
yoxelyoxel
1.06beta:beta
yoxelyoxel
1.07beta:beta
yoxelyoxel
1.08beta:beta
yoxelyoxel
1.09beta:beta
yoxelyoxel
1.10beta:beta
yoxelyoxel
1.11beta:beta
yoxelyoxel
1.12beta:beta
yoxelyoxel
1.13beta:beta
yoxelyoxel
1.14beta:beta
yoxelyoxel
1.15beta:beta
yoxelyoxel
1.16beta:beta
yoxelyoxel
1.17beta:beta
yoxelyoxel
1.18beta:beta
yoxelyoxel
1.19beta:beta
yoxelyoxel
1.20
yoxelyoxel
1.20beta:beta
yoxelyoxel
1.21
yoxelyoxel
1.21beta:beta
yoxelyoxel
1.22
yoxelyoxel
1.22beta:beta
𝑥
= Vulnerable software versions