CVE-2009-0517
Summary
| CVE | CVE-2009-0517 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-11 00:30:03 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpslash | Phpslash | All | All | All | All |
| Application | Phpslash | Phpslash | 0.5.3.2 | All | All | All |
| Application | Phpslash | Phpslash | 0.6 | All | All | All |
| Application | Phpslash | Phpslash | 0.6.1 | All | All | All |
| Application | Phpslash | Phpslash | 0.6.2 | All | All | All |
| Application | Phpslash | Phpslash | 0.61 | All | All | All |
| Application | Phpslash | Phpslash | 0.7.1 | All | All | All |
| Application | Phpslash | Phpslash | 0.7.2 | All | All | All |
| Application | Phpslash | Phpslash | 0.8.0 | All | All | All |
| Application | Phpslash | Phpslash | 0.8.1 | All | All | All |
| Application | Phpslash | Phpslash | 065 | All | All | All |
| Application | Phpslash | Phpslash | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| phpslash <= 0.8.1.1 Remote Code Execution Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| phpSlash 'fields' Parameter Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| phpSlash "generic()" PHP Code Injection Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/51727 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.