CVE-2008-6748

Megacubo - Code Injection

Title source: rule

Description

Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.

Exploits (2)

exploitdb WORKING POC VERIFIED
by JJunior · htmlremotewindows
https://www.exploit-db.com/exploits/7630
exploitdb WORKING POC VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/7623

Scores

EPSS 0.1531
EPSS Percentile 94.6%

Details

CWE
CWE-94
Status published
Products (1)
megacubo/megacubo 5.0.7
Published Apr 24, 2009
Tracked Since Feb 18, 2026