CVE-2008-6446: Code Injection
Published Mar 9, 2009
·Updated
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.
Affected Software
1 affected component
Geniuscyber Maxsite
Event History
Mar 9, 2009
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6446?
CVE-2008-6446 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2008-6446?
To fix CVE-2008-6446, update to the latest version of the CMS MAXSITE that addresses this vulnerability.
3
What is the impact of CVE-2008-6446?
The impact of CVE-2008-6446 allows remote attackers to execute arbitrary PHP code on the server.
4
Which software is affected by CVE-2008-6446?
CVE-2008-6446 affects the Guestbook component of the CMS MAXSITE.
5
Can CVE-2008-6446 be exploited remotely?
Yes, CVE-2008-6446 can be exploited remotely by attackers through the message parameter in the guestbook.