CVE-2008-0300

Mapbender - Code Injection

Title source: rule
STIX 2.1

Description

mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RedTeam Pentesting · textwebappsphp
https://www.exploit-db.com/exploits/5232

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5232
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28195
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41131
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29329

Scores

EPSS 0.0474
EPSS Percentile 89.5%

Details

CWE
CWE-94
Status published
Products (5)
mapbender/mapbender 2.4
mapbender/mapbender 2.4.1
mapbender/mapbender 2.4.2
mapbender/mapbender 2.4.3
mapbender/mapbender 2.4.4
Published Mar 11, 2008
Tracked Since Feb 18, 2026