peter bassill · operator
$ cve CVE-2008-5090 JSON

CVE-2008-5090 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.6% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2008-11-14
Last modified2026-06-16

Affected (1)

VendorProduct
anelectronadvanced electron forum

Public exploits

SourceTitleDate
exploit-dbAdvanced Electron Forum 1.0.6 - Remote Code Execution2008-09-20

References

→ the Explorer  ·  watch your stack  ·  NVD