PT-2009-2121 · Oxybox · Oxybox

Gold_M

·

Published

2009-04-07

·

Updated

2017-09-29

·

CVE-2008-6651

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OxYBox version 0.85
Description A static code injection issue exists, allowing remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter in edithistory.php.
Recommendations For OxYBox version 0.85, avoid using the oxymsg parameter in the affected edithistory.php file until a fix is available. As a temporary workaround, consider restricting access to edithistory.php to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6651

Affected Products

Oxybox