CVE-2008-3298 Information

Description

SocialEngine (SE) before 2.83 grants certain write privileges for templates which allows remote authenticated administrators to execute arbitrary PHP code.

Reference

http://secunia.com/advisories/31203 http://securityreason.com/securityalert/4035 http://www.securityfocus.com/archive/1/494638/100/0/threaded http://www.socialengine.net/news.php https://exchange.xforce.ibmcloud.com/vulnerabilities/43959

Share on: