CVE-2008-5090
Summary
| CVE | CVE-2008-5090 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-14 19:20:53 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Anelectron | Advanced Electron Forum | 1.0.1 | All | All | All |
| Application | Anelectron | Advanced Electron Forum | 1.0.2 | All | All | All |
| Application | Anelectron | Advanced Electron Forum | 1.0.3 | All | All | All |
| Application | Anelectron | Advanced Electron Forum | 1.0.4 | All | All | All |
| Application | Anelectron | Advanced Electron Forum | 1.0.5 | All | All | All |
| Application | Anelectron | Advanced Electron Forum | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advanced Electron Forum PHP Code Execution Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| AEF 1.0.7 is out! | af854a3a-2127-422b-91ae-364da2661108 | www.anelectron.com | Vendor Advisory |
| Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityReason - Advanced Electron Forum <= 1.0.6 Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Contact Support | af854a3a-2127-422b-91ae-364da2661108 | www.gulftech.org | |
| Advanced Electron Forum 1.0.6 - Remote Code Execution - PHP webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.