CVE-2010-4884: Code Injection
Published Oct 7, 2011
·Updated
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the scriptpfad parameter.
Affected Software
1 affected component
Hinnendahl Gaestebuch=1.2
Event History
Oct 7, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4884?
CVE-2010-4884 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2010-4884?
To fix CVE-2010-4884, update to a version of Gaestebuch that is not vulnerable, as version 1.2 is affected.
3
What software is affected by CVE-2010-4884?
CVE-2010-4884 affects Gaestebuch version 1.2.
4
What kind of attack can exploit CVE-2010-4884?
CVE-2010-4884 can be exploited by remote attackers to execute arbitrary PHP code.
5
What parameter is involved in CVE-2010-4884?
The script_pfad parameter in guestbook/gbook.php is involved in the CVE-2010-4884 vulnerability.