CVE-2008-3093
Phplizardo Imperialbb < 2.3.5 - Code Injection
Title source: ruleDescription
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by PHPLizardo · phpwebappsphp
https://www.exploit-db.com/exploits/6008
References (5)
Scores
EPSS
0.0412
EPSS Percentile
88.7%
Details
CWE
CWE-94
Status
published
Products (1)
phplizardo/imperialbb
< 2.3.5
Published
Jul 09, 2008
Tracked Since
Feb 18, 2026