Lucene search

K
cveMitreCVE-2008-1609
HistoryApr 01, 2008 - 4:44 p.m.

CVE-2008-1609

2008-04-0116:44:00
CWE-94
mitre
web.nvd.nist.gov
31
cve
2008
1609
php
remote file inclusion
jaf cms 4.0 rc2
vulnerability
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.043

Percentile

92.5%

Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php, (b) headlines.php, and © main.php in forum/, and (2) main_dir parameter to forum/forum.php. NOTE: other main_dir vectors are already covered by CVE-2006-7127.

Affected configurations

Nvd
Node
jaf_cmsjaf_cmsMatch4.0_rc2
VendorProductVersionCPE
jaf_cmsjaf_cms4.0_rc2cpe:2.3:a:jaf_cms:jaf_cms:4.0_rc2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.043

Percentile

92.5%