CVE-2008-6958: Code Injection
Published Aug 12, 2009
·Updated
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.
Affected Software
2 affected components
Comsenz Crossday Discuz\! Board=6.0.1
Comsenz Crossday Discuz\! Board=7.0
Event History
Aug 12, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6958?
CVE-2008-6958 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2008-6958?
To mitigate CVE-2008-6958, update to the latest version of Discuz! Board that addresses this vulnerability.
3
What are the affected versions of Discuz! related to CVE-2008-6958?
CVE-2008-6958 affects Discuz! Board versions 6.x and 7.x.
4
Who can exploit CVE-2008-6958?
CVE-2008-6958 can be exploited by remote authenticated users with access to the application.
5
What kind of attack is possible with CVE-2008-6958?
CVE-2008-6958 allows authenticated users to execute arbitrary PHP code on the server.