CVE-2008-3239

PHPizabi 0.848b C1 HFP1 - RCE

Title source: llm

Description

Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Inphex · perlwebappsphp
https://www.exploit-db.com/exploits/6085

Scores

EPSS 0.0463
EPSS Percentile 89.3%

Details

CWE
CWE-20
Status published
Products (1)
phpizabi/phpizabi 0.848b c1 (2 CPE variants)
Published Jul 21, 2008
Tracked Since Feb 18, 2026