CVE-2008-6287 Information

Description

Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php (2) SQLController.php (3) SetupController.php (4) VideoController.php and (5) ViewController.php in controllers/.

Reference

http://www.securityfocus.com/bid/32554 http://www.vupen.com/english/advisories/2008/3289 https://exchange.xforce.ibmcloud.com/vulnerabilities/46939 https://www.exploit-db.com/exploits/7310

Share on: