CVE-2010-4878: Code Injection
Published Oct 7, 2011
·Updated
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the scriptpfad parameter.
Affected Software
1 affected component
Hinnendahl Kontakt Formular=1.1
Event History
Oct 7, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4878?
CVE-2010-4878 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2010-4878?
To fix CVE-2010-4878, it is recommended to upgrade to the latest version of Kontakt Formular that addresses this vulnerability.
3
What does CVE-2010-4878 affect?
CVE-2010-4878 specifically affects Kontakt Formular version 1.1 and allows remote file inclusion.
4
Who is vulnerable to CVE-2010-4878?
Any website using Kontakt Formular 1.1 is vulnerable to CVE-2010-4878 if not properly secured.
5
What type of attack is possible with CVE-2010-4878?
CVE-2010-4878 allows attackers to execute arbitrary PHP code on the server, leading to possible full system compromise.