CVE-2008-4645
Phpwebgallery < 1.7.2 - Code Injection
Title source: ruleDescription
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.
Exploits (1)
Scores
EPSS
0.0219
EPSS Percentile
84.4%
Details
CWE
CWE-94
Status
published
Products (19)
phpwebgallery/phpwebgallery
1.0
phpwebgallery/phpwebgallery
1.1
phpwebgallery/phpwebgallery
1.2.1
phpwebgallery/phpwebgallery
1.3.0
phpwebgallery/phpwebgallery
1.3.1
phpwebgallery/phpwebgallery
1.3.2
phpwebgallery/phpwebgallery
1.3.3
phpwebgallery/phpwebgallery
1.3.4
phpwebgallery/phpwebgallery
1.4.0
phpwebgallery/phpwebgallery
1.4.1
... and 9 more
Published
Oct 22, 2008
Tracked Since
Feb 18, 2026