peter bassill · operator
$ cve CVE-2008-2044 JSON

CVE-2008-2044 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 11.4% (pctl 96)

Patch early

A public exploit exists.

Description

includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS11.35% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2008-05-01
Last modified2026-06-16

Affected (1)

VendorProduct
netofficedwins

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD