CVE-2008-6138

WebBiscuits Modules Controller <1.1 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/6703

Scores

EPSS 0.0234
EPSS Percentile 84.6%

Classification

CWE
CWE-94
Status draft

Affected Products (1)

webbiscuits/modules_controller < 1.1

Timeline

Published Feb 14, 2009
Tracked Since Feb 18, 2026