CVE-2008-7123

Zkup - Code Injection

Title source: rule

Description

Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which bypasses the regular expression check.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/5220

Scores

EPSS 0.0183
EPSS Percentile 83.0%

Details

CWE
CWE-94
Status published
Products (4)
zkup/zkup 2.0
zkup/zkup 2.01
zkup/zkup 2.02
zkup/zkup 2.03
Published Aug 31, 2009
Tracked Since Feb 18, 2026