CVE-2008-1860
LokiCMS <0.3.3 - Code Injection
Title source: llmDescription
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0548
EPSS Percentile
90.2%
Details
CWE
CWE-94
Status
published
Products (8)
lokicms/lokicms
0.1.0
lokicms/lokicms
0.1.0rc1
lokicms/lokicms
0.2.0
lokicms/lokicms
0.3.0
lokicms/lokicms
0.3.1b1
lokicms/lokicms
0.3.1b2
lokicms/lokicms
0.3.2b1
lokicms/lokicms
< 0.3.3
Published
Apr 17, 2008
Tracked Since
Feb 18, 2026