CVE-2008-0390: Code Injection
stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0390?
CVE-2008-0390 is classified as a critical vulnerability due to the potential for arbitrary PHP code execution.
How do I fix CVE-2008-0390?
To fix CVE-2008-0390, update AuraCMS to the latest version or apply security patches that address the vulnerability.
Which software is affected by CVE-2008-0390?
CVE-2008-0390 affects AuraCMS version 1.62 and the Mod Block Statistik plugin for AuraCMS.
What type of attack is associated with CVE-2008-0390?
CVE-2008-0390 involves remote code injection through manipulation of the X-Forwarded-For HTTP header.
Can CVE-2008-0390 lead to unauthorized access?
Yes, CVE-2008-0390 can lead to unauthorized access and control over affected servers due to code execution capabilities.