CVE-2008-2481: Code Injection
Published May 28, 2008
·Updated
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when registerglobals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfigauth[phpbbpath] parameter.
Affected Software
2 affected components
phpRaider phpRaider=1.0.7
phpRaider phpRaider=1.0.7a
Event History
May 28, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2481?
CVE-2008-2481 is considered critical due to its ability to allow remote attackers to execute arbitrary PHP code.
2
How do I fix CVE-2008-2481?
To fix CVE-2008-2481, it is recommended to disable register_globals and upgrade to a patched version of phpRaider.
3
Which versions of phpRaider are affected by CVE-2008-2481?
CVE-2008-2481 affects phpRaider versions 1.0.7 and 1.0.7a.
4
What type of vulnerability is CVE-2008-2481?
CVE-2008-2481 is a remote file inclusion vulnerability.
5
What parameter is exploited in CVE-2008-2481?
CVE-2008-2481 is exploited through the pConfig_auth[phpbb_path] parameter.