CVE-2009-0517

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
11/02/2009
Last modified:
11/10/2018

Description

Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpslash:phpslash:*:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:*:*:*:*:*:*:*:* 0.8.1.1 (including)
cpe:2.3:a:phpslash:phpslash:0.5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.6:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.7.1:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:0.61:*:*:*:*:*:*:*
cpe:2.3:a:phpslash:phpslash:065:*:*:*:*:*:*:*