CVE-2008-6748
Megacubo - Code Injection
Title source: ruleDescription
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by JJunior · htmlremotewindows
https://www.exploit-db.com/exploits/7630
exploitdb
WORKING POC
VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/7623
References (7)
Scores
EPSS
0.1531
EPSS Percentile
94.6%
Details
CWE
CWE-94
Status
published
Products (1)
megacubo/megacubo
5.0.7
Published
Apr 24, 2009
Tracked Since
Feb 18, 2026