CVE-2008-2769: Code Injection
Published Jun 18, 2008
·Updated
PHP remote file inclusion vulnerability in authentication/smf/smf.functions.php in Simple Machines phpRaider 1.0.6 and 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the pConfigauth[smfpath] parameter.
Affected Software
2 affected components
phpRaider phpRaider=1.0.6
phpRaider phpRaider=1.0.7
Event History
Jun 18, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2769?
CVE-2008-2769 has a high severity level due to its potential to allow remote code execution.
2
How do I fix CVE-2008-2769?
To mitigate CVE-2008-2769, update your Simple Machines phpRaider to version 1.0.8 or later.
3
What software versions are affected by CVE-2008-2769?
CVE-2008-2769 affects Simple Machines phpRaider versions 1.0.6 and 1.0.7.
4
What type of vulnerability is CVE-2008-2769?
CVE-2008-2769 is a remote file inclusion vulnerability.
5
Who can exploit CVE-2008-2769?
Remote attackers can exploit CVE-2008-2769 by manipulating the pConfig_auth[smf_path] parameter.