PT-2008-3075 · Oocomments · Oocomments

CVE-2008-1511

·

Published

2008-03-25

·

Updated

2025-04-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ooComments version 1.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for classes/class admin.php and classes/class comments.php, such as the API endpoint "/classes/class admin.php" and "/classes/class comments.php".
Recommendations For ooComments version 1.0, consider restricting access to the PathToComment parameter in the affected classes/class admin.php and classes/class comments.php files until a patch is available. As a temporary workaround, avoid using the PathToComment parameter in the affected API endpoints.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1511

Affected Products

Oocomments