CVE-2008-1609 Information
Feb 14, 2021
cve
Description
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php (b) headlines.php and (c) main.php in forum/ and (2) main_dir parameter to forum/forum.php. NOTE: other main_dir vectors are already covered by CVE-2006-7127.
Reference
http://www.securityfocus.com/archive/1/490162/100/0/threaded http://www.securityfocus.com/archive/1/490183/100/0/threaded http://www.securityfocus.com/bid/28476 https://exchange.xforce.ibmcloud.com/vulnerabilities/41753 https://www.exploit-db.com/exploits/2474/ https://www.exploit-db.com/exploits/5317
Share on: