{"api_version":"1","generated_at":"2026-04-24T02:43:38+00:00","cve":"CVE-2008-5090","urls":{"html":"https://cve.report/CVE-2008-5090","api":"https://cve.report/api/cve/CVE-2008-5090.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5090","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5090"},"summary":{"title":"CVE-2008-5090","description":"Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-14 19:20:53","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/31978","name":"http://secunia.com/advisories/31978","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Advanced Electron Forum PHP Code Execution Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/496552/100/0/threaded","name":"http://www.securityfocus.com/archive/1/496552/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.anelectron.com/board/index.php?tid=3282","name":"http://www.anelectron.com/board/index.php?tid=3282","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"AEF 1.0.7 is out!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31268","name":"http://www.securityfocus.com/bid/31268","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Advanced Electron Forum BBCode 'preg_replace' PHP Code Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45270","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45270","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4598","name":"http://securityreason.com/securityalert/4598","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Advanced Electron Forum <= 1.0.6 Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gulftech.org/?node=research&article_id=00131-09202008","name":"http://www.gulftech.org/?node=research&article_id=00131-09202008","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contact Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/6499","name":"https://www.exploit-db.com/exploits/6499","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advanced Electron Forum 1.0.6 - Remote Code Execution - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5090","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5090","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"1.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"1.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"1.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5090","vulnerable":"1","versionEndIncluding":"1.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anelectron","cpe5":"advanced_electron_forum","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:40:17.234Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.anelectron.com/board/index.php?tid=3282"},{"name":"aef-pregreplace-code-execution(45270)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45270"},{"name":"20080920 Advanced Electron Forum <= 1.0.6 Remote Code Execution","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/496552/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gulftech.org/?node=research&article_id=00131-09202008"},{"name":"4598","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4598"},{"name":"31978","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31978"},{"name":"6499","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/6499"},{"name":"31268","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31268"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.anelectron.com/board/index.php?tid=3282"},{"name":"aef-pregreplace-code-execution(45270)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45270"},{"name":"20080920 Advanced Electron Forum <= 1.0.6 Remote Code Execution","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/496552/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.gulftech.org/?node=research&article_id=00131-09202008"},{"name":"4598","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4598"},{"name":"31978","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31978"},{"name":"6499","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/6499"},{"name":"31268","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31268"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5090","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.anelectron.com/board/index.php?tid=3282","refsource":"CONFIRM","url":"http://www.anelectron.com/board/index.php?tid=3282"},{"name":"aef-pregreplace-code-execution(45270)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45270"},{"name":"20080920 Advanced Electron Forum <= 1.0.6 Remote Code Execution","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/496552/100/0/threaded"},{"name":"http://www.gulftech.org/?node=research&article_id=00131-09202008","refsource":"MISC","url":"http://www.gulftech.org/?node=research&article_id=00131-09202008"},{"name":"4598","refsource":"SREASON","url":"http://securityreason.com/securityalert/4598"},{"name":"31978","refsource":"SECUNIA","url":"http://secunia.com/advisories/31978"},{"name":"6499","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/6499"},{"name":"31268","refsource":"BID","url":"http://www.securityfocus.com/bid/31268"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5090","datePublished":"2008-11-14T19:00:00.000Z","dateReserved":"2008-11-14T00:00:00.000Z","dateUpdated":"2024-08-07T10:40:17.234Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-14 19:20:53","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.6","matchCriteriaId":"346A0065-57B5-44C8-9A0D-B681B653935A"},{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"68188511-BA5A-454A-8959-A754AA7147BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"39DBB3C6-A59B-46E8-AE2E-B4F90B4327E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"B729A246-6642-44BD-8842-B676E6F9D0D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"938E89B8-C921-44B5-B97F-D756CC5607C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:anelectron:advanced_electron_forum:1.0.5:*:*:*:*:*:*:*","matchCriteriaId":"D35C1FAF-9F98-42A0-B457-E5949AEA8864"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5090","Ordinal":"1","Title":"CVE-2008-5090","CVE":"CVE-2008-5090","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5090","Ordinal":"1","NoteData":"Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.","Type":"Description","Title":"CVE-2008-5090"},{"CveYear":"2008","CveId":"5090","Ordinal":"2","NoteData":"2008-11-14","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5090","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}