Code Execution Vulnerability in Crossday Discuz! Board by Crossday
CVE-2008-6958

Currently unrated

Key Information:

Vendor

Comsenz

Vendor
CVE Published:
12 August 2009

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2008-6958?

The Crossday Discuz! Board versions 6.x and 7.x contain a vulnerability in the wap/index.php script, which allows remote authenticated users to execute arbitrary PHP code. This is accomplished through manipulation of the creditsformula parameter, leading to potential exploitation of the application. Proper input validation and sanitization measures should be implemented to mitigate this risk.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.