CVE-2008-6651

Oxyproject Oxybox - Code Injection

Title source: rule
STIX 2.1

Description

Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/5524

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5524
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28992
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42110

Scores

EPSS 0.0430
EPSS Percentile 88.9%

Details

CWE
CWE-94
Status published
Products (1)
oxyproject/oxybox 0.85
Published Apr 07, 2009
Tracked Since Feb 18, 2026