← Back

CVE-2008-5060

nvd nist
Published: Nov 13, 2008Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.

Affected (16)

1 product
Modernbill
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Modernbill
Up to 4.4
Up to 4.4.0
Version 2.01
Version 2.02s
Version 3.0 beta
Version 3.1.0
Version 3.1.3
Version 4.0.1 rc7
Version 4.0.1 rc8
Version 4.0.2
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.2.1
Version 4.3.0
Version 4.3.2

References (8)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.