CVE-2008-3764 Information

Description

Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via the test parameter and probably arbitrary parameters to chat.php.

Reference

http://demos.turnkeywebtools.com/phplivehelper/docs/change_log.txt http://secunia.com/advisories/31521 http://securityreason.com/securityalert/4178 http://www.gulftech.org/?node=research&article_id=00124-08162008 http://www.securityfocus.com/archive/1/495542/100/0/threaded http://www.securityfocus.com/bid/30729 https://exchange.xforce.ibmcloud.com/vulnerabilities/44571 https://www.exploit-db.com/exploits/6261

Share on: