← Back

CVE-2008-5186

nvd nist
Published: Nov 21, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate CVE identifiers would be created for web applications that integrate GeSHi in a way that allows control of the default language path

Affected (32)

Products: Geshi: Geshi
1 product
Geshi
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Geshi
Up to 1.0.8
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.2_beta_1
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7.10
Version 1.0.7.11
Version 1.0.7.12
Version 1.0.7.13
Version 1.0.7.14
Version 1.0.7.15
Version 1.0.7.16
Version 1.0.7.17
Version 1.0.7.18
Version 1.0.7.19
Version 1.0.7.1
Version 1.0.7.20
Version 1.0.7.21
Version 1.0.7.22
Version 1.0.7.2
Version 1.0.7.3
Version 1.0.7.4
Version 1.0.7.5
Version 1.0.7.6
Version 1.0.7.7
Version 1.0.7.8
Version 1.0.7.9
Version 1.0.7

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.