The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characterswhich allows remote authenticated users to obtain sensitive information via a comment containing a macroas demonstrated by a "{user.password}" comment in the profile of the admin user.
The following products are affected by CVE-2008-2018
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affectedthe information is not represented in the table below.
ID
Vendor
Product
Action
1
Phpizabi
phpizabi
Scoring
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework
for assessing the severity of vulnerabilities in software and systems.
We collect and displays CVSS scores from various sources for each CVE.
While CVE identifies
specific instances of vulnerabilitiesCWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2008-2018 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification
(CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patternswhich are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2008-2018
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection
of public exploits and proof-of-conceptswhich have been published on GitHub (sorted by the most recently
updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2008-2018 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2008-2018 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerabilityand for identifying the most recent changes that may
impact the vulnerability's severityexploitabilityor other characteristics.
CVE Modified
by af854a3a-2127-422b-91ae-364da2661108
EPSS is a daily estimate of the probability of exploitation activity
being observed over the next 30 days. Following chart shows the EPSS
score history of the vulnerability.
CVSS
Vulnerability Scoring Details
Base CVSS Score: 4
Access Vector
Access Complexity
Authentication
Confidentiality Impact
Integrity Impact
Availability Impact
EPSS
Exploit Prediction
EPSS is a daily estimate of the probability of exploitation
activity
being observed over the next 30 days.