peter bassill · operator
$ cve CVE-2008-6934 JSON

CVE-2008-6934 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.91% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-08-11
Last modified2026-06-16

Affected (1)

VendorProduct
sansuartfree simple guestbook php script

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD