Zero-day Vulnerability Database

Change view:

Zero-day vulnerabilities discovered: 1

Remote PHP including in PHPCow
CVE-2008-5227

Remote PHP including

The vulnerability allows a remote attacker to execute arbitrary PHP code on the target application.

The weakness exists due to improper validation of input passed via the "skin_file" HTTP parameter to "templateie_install.class.php" script. A remote attacker can send a specially-crafted HTTP request to vulnerable script, specify a malicious file from a remote system and execute arbitrary PHP code on the system.

Successful exploitation of the vulnerability results in arbitrary PHP code execution on the vulnerable application.

Note: the vulnerability was being actively exploited.

Software: PHPCow

Vulnerability Scanning SaaS

Vulnerability scanning SaaS service is online 3-rd generation vulnerability scanner with scheduled assessments and vulnerability subscription. You can use service to check security of your network perimeter.