{"api_version":"1","generated_at":"2026-07-23T11:10:39+00:00","cve":"CVE-2009-0517","urls":{"html":"https://cve.report/CVE-2009-0517","api":"https://cve.report/api/cve/CVE-2009-0517.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0517","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0517"},"summary":{"title":"CVE-2009-0517","description":"Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-11 00:30:03","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/7948","name":"https://www.exploit-db.com/exploits/7948","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"phpslash <= 0.8.1.1 Remote Code Execution Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48441","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48441","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33572","name":"http://www.securityfocus.com/bid/33572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"phpSlash 'fields' Parameter Remote Command Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/500664/100/0/threaded","name":"http://www.securityfocus.com/archive/1/500664/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33717","name":"http://secunia.com/advisories/33717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"phpSlash \"generic()\" PHP Code Injection Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/51727","name":"http://osvdb.org/51727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0517","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0517","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.5.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.61","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.7.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"0.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"065","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"517","vulnerable":"1","versionEndIncluding":"0.8.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpslash","cpe5":"phpslash","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:40:04.279Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33717","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33717"},{"name":"33572","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33572"},{"name":"phpslash-generic-code-execution(48441)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48441"},{"name":"7948","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/7948"},{"name":"51727","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/51727"},{"name":"20090201 phpslash <= 0.8.1.1 Remote Code Execution Exploit","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/500664/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-02-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"33717","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33717"},{"name":"33572","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33572"},{"name":"phpslash-generic-code-execution(48441)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48441"},{"name":"7948","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/7948"},{"name":"51727","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/51727"},{"name":"20090201 phpslash <= 0.8.1.1 Remote Code Execution Exploit","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/500664/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0517","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"33717","refsource":"SECUNIA","url":"http://secunia.com/advisories/33717"},{"name":"33572","refsource":"BID","url":"http://www.securityfocus.com/bid/33572"},{"name":"phpslash-generic-code-execution(48441)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48441"},{"name":"7948","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/7948"},{"name":"51727","refsource":"OSVDB","url":"http://osvdb.org/51727"},{"name":"20090201 phpslash <= 0.8.1.1 Remote Code Execution Exploit","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/500664/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0517","datePublished":"2009-02-11T00:00:00.000Z","dateReserved":"2009-02-10T00:00:00.000Z","dateUpdated":"2024-08-07T04:40:04.279Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-11 00:30:03","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:*:*:*:*:*:*:*:*","matchCriteriaId":"385ABF67-157E-4592-80E7-8399C4D72879"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:*:*:*:*:*:*:*:*","versionEndIncluding":"0.8.1.1","matchCriteriaId":"9CA61227-D278-4502-92ED-24C3E900FEC5"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.5.3.2:*:*:*:*:*:*:*","matchCriteriaId":"DC8FB8A1-BE41-4E62-88E9-AB15246AB0FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.6:*:*:*:*:*:*:*","matchCriteriaId":"68D5F330-5C61-4627-B925-272A357E1338"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.6.1:*:*:*:*:*:*:*","matchCriteriaId":"C9493398-C12A-439A-9836-0D62F6510D0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.6.2:*:*:*:*:*:*:*","matchCriteriaId":"506762E9-EAA6-4AFE-8F78-3FA6491C27F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.7.1:*:*:*:*:*:*:*","matchCriteriaId":"31BDD3F6-789D-48AB-AD5C-137BB5D53BB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.7.2:*:*:*:*:*:*:*","matchCriteriaId":"0292084B-B04A-4465-936B-51FFFE5328C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.8.0:*:*:*:*:*:*:*","matchCriteriaId":"0B370B91-6B3C-4423-ABE5-840999099D0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.8.1:*:*:*:*:*:*:*","matchCriteriaId":"703FD7D9-5D17-4C57-882A-8EF33CDE44F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:0.61:*:*:*:*:*:*:*","matchCriteriaId":"BF4822EC-378F-44B5-90E3-5B3F82247C92"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpslash:phpslash:065:*:*:*:*:*:*:*","matchCriteriaId":"1BCF8850-3160-45C9-AA16-C785AFDB246C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"517","Ordinal":"1","Title":"CVE-2009-0517","CVE":"CVE-2009-0517","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"517","Ordinal":"1","NoteData":"Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2009-0517"},{"CveYear":"2009","CveId":"517","Ordinal":"2","NoteData":"2009-02-10","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"517","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}