{"api_version":"1","generated_at":"2026-07-23T14:51:18+00:00","cve":"CVE-2009-0677","urls":{"html":"https://cve.report/CVE-2009-0677","api":"https://cve.report/api/cve/CVE-2009-0677.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0677","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0677"},"summary":{"title":"CVE-2009-0677","description":"avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-22 22:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.exploit-db.com/exploits/8068","name":"https://www.exploit-db.com/exploits/8068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ravennuke 2.3.0 - Multiple Vulnerabilities - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.waraxe.us/advisory-72.html","name":"http://www.waraxe.us/advisory-72.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0","mime":"text/html","httpstatus":"200","archivestatus":"504"},{"url":"http://secunia.com/advisories/33928","name":"http://secunia.com/advisories/33928","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"RavenNuke avartarlist.php PHP Code Injection Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/500988/100/0/threaded","name":"http://www.securityfocus.com/archive/1/500988/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33787","name":"http://www.securityfocus.com/bid/33787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RavenNuke Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad","name":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"RNv2.30.01 Has Been Released - Must Read For Security Update - Ravens PHP Scripts","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/52007","name":"http://www.osvdb.org/52007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48789","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48789","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0677","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0677","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"677","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ravenphpscripts","cpe5":"ravennuke","cpe6":"2.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:40:05.334Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33787","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33787"},{"name":"33928","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33928"},{"name":"52007","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/52007"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad"},{"name":"20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/500988/100/0/threaded"},{"name":"8068","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/8068"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.waraxe.us/advisory-72.html"},{"name":"ravennuke-avatarlist-code-execution(48789)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48789"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-02-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"33787","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33787"},{"name":"33928","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33928"},{"name":"52007","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/52007"},{"tags":["x_refsource_CONFIRM"],"url":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad"},{"name":"20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/500988/100/0/threaded"},{"name":"8068","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/8068"},{"tags":["x_refsource_MISC"],"url":"http://www.waraxe.us/advisory-72.html"},{"name":"ravennuke-avatarlist-code-execution(48789)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48789"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0677","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"33787","refsource":"BID","url":"http://www.securityfocus.com/bid/33787"},{"name":"33928","refsource":"SECUNIA","url":"http://secunia.com/advisories/33928"},{"name":"52007","refsource":"OSVDB","url":"http://www.osvdb.org/52007"},{"name":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad","refsource":"CONFIRM","url":"http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad"},{"name":"20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/500988/100/0/threaded"},{"name":"8068","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/8068"},{"name":"http://www.waraxe.us/advisory-72.html","refsource":"MISC","url":"http://www.waraxe.us/advisory-72.html"},{"name":"ravennuke-avatarlist-code-execution(48789)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48789"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0677","datePublished":"2009-02-22T22:00:00.000Z","dateReserved":"2009-02-22T00:00:00.000Z","dateUpdated":"2024-08-07T04:40:05.334Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-22 22:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ravenphpscripts:ravennuke:2.30:*:*:*:*:*:*:*","matchCriteriaId":"24561E2B-3481-4E0C-8115-14A7FBB2F176"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"677","Ordinal":"1","Title":"CVE-2009-0677","CVE":"CVE-2009-0677","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"677","Ordinal":"1","NoteData":"avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.","Type":"Description","Title":"CVE-2009-0677"},{"CveYear":"2009","CveId":"677","Ordinal":"2","NoteData":"2009-02-22","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"677","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}