Gbx · Gravity Board X · CVE-2009-1278
**Name of the Vulnerable Software and Affected Versions**
Gravity Board X (GBX) version 2.0 BETA
**Description**
The issue allows remote attackers to inject arbitrary PHP code into config.php via the configure action to "index.php". This is a static code injection vulnerability in the forms/ajax/configure.php file.
**Recommendations**
For Gravity Board X (GBX) version 2.0 BETA, as a temporary workaround, consider disabling access to the vulnerable "configure.php" file until a patch is available. Restrict access to the `configure` action in "index.php" to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.