CVE-2008-1963

Quate Grape Web Statistics 0.2a - Remote Code Execution via Location Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1963. PoCs published by MajnOoNxHaCkEr.

AI-analyzed exploit summary This is a writeup describing a remote file inclusion vulnerability in Grape Web Statistics. The vulnerability is in the 'functions.php' file, where the 'location' parameter is not properly sanitized, allowing an attacker to include remote files.

Description

PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by MajnOoNxHaCkEr · textwebappsphp
https://www.exploit-db.com/exploits/5463

This is a writeup describing a remote file inclusion vulnerability in Grape Web Statistics. The vulnerability is in the 'functions.php' file, where the 'location' parameter is not properly sanitized, allowing an attacker to include remote files.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Grape Web Statistics
No auth needed
Prerequisites: A vulnerable version of Grape Web Statistics · Remote file hosting
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5463
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41883
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28838

Scores

EPSS 0.3903
EPSS Percentile 98.4%

Details

CWE
CWE-94
Status published
Products (1)
quate/grape_web_statistics 0.2a
Published Apr 25, 2008
Tracked Since Feb 18, 2026