peter bassill · operator
$ cve CVE-2008-5322 JSON

CVE-2008-5322 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS2.51% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2008-12-03
Last modified2026-06-16

Affected (1)

VendorProduct
easy-scriptwysi wiki wyg

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD