CVE-2008-2638 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 3.86% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-06-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| 1-script | 1-book |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | 1Book Guestbook Script 1.0.1 - Code Execution | 2008-06-03 |
References
- http://1scripts.net/php-scripts/index.php?p=16
- http://secunia.com/advisories/30146
- http://www.vupen.com/english/advisories/2008/1735/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42854
- https://www.exploit-db.com/exploits/5736
- http://1scripts.net/php-scripts/index.php?p=16
- http://secunia.com/advisories/30146
- http://www.vupen.com/english/advisories/2008/1735/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42854
- https://www.exploit-db.com/exploits/5736
→ the Explorer · watch your stack · NVD