← Back

CVE-2009-0517

nvd nist
Published: Feb 11, 2009Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.

Affected (12)

Products: Phpslash: Phpslash
1 product
Phpslash
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Phpslash
All versions
Up to 0.8.1.1
Version 0.5.3.2
Version 0.6.1
Version 0.6.2
Version 0.61
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.8.0
Version 0.8.1
Version 065

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.