CVE-2009-0517

phpSlash <0.8.1.1 - Code Injection

Title source: llm

Description

Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/7948

Scores

EPSS 0.6923
EPSS Percentile 98.7%

Details

CWE
CWE-94
Status published
Products (11)
phpslash/phpslash
phpslash/phpslash 0.5.3.2
phpslash/phpslash 0.6
phpslash/phpslash 0.6.1
phpslash/phpslash 0.6.2
phpslash/phpslash 0.7.1
phpslash/phpslash 0.7.2
phpslash/phpslash 0.8.0
phpslash/phpslash 0.8.1
phpslash/phpslash 0.61
... and 1 more
Published Feb 11, 2009
Tracked Since Feb 18, 2026