Vulnerability Details CVE-2008-4645
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.3%
CVSS Severity
CVSS v2 Score 9.0
Products affected by CVE-2008-4645
-
cpe:2.3:a:phpwebgallery:phpwebgallery:*
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.2.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.3.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.3.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.3.2
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.3.3
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.3.4
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.4.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.4.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.5.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.5.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.5.2
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.6.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.6.1
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.6.2
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.7.0
-
cpe:2.3:a:phpwebgallery:phpwebgallery:1.7.1