← Back

CVE-2008-5071

nvd nist
Published: Nov 14, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter.

Affected (21)

Products: Yoxel: Yoxel
1 product
Yoxel
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Yoxel
Up to 1.23beta
Version 1.06beta
Version 1.07beta
Version 1.08beta
Version 1.09beta
Version 1.10beta
Version 1.11beta
Version 1.12beta
Version 1.13beta
Version 1.14beta
Version 1.15beta
Version 1.16beta
Version 1.17beta
Version 1.18beta
Version 1.19beta
Version 1.20
Version 1.20beta
Version 1.21
Version 1.21beta
Version 1.22
Version 1.22beta

References (8)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.