ID

VAR-200802-0355


CVE

CVE-2008-0566


TITLE

DeltaScripts PHP Links of includes/smarty.php In PHP Remote file inclusion vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2008-002681

DESCRIPTION

PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter. This may facilitate a compromise of the application and the underlying system; other attacks are also possible. This issue affects PHP Links 1.3 and prior versions

Trust: 1.89

sources: NVD: CVE-2008-0566 // JVNDB: JVNDB-2008-002681 // BID: 27529

AFFECTED PRODUCTS

vendor:deltascriptsmodel:php linksscope:eqversion:1.3

Trust: 1.9

vendor:deltascriptsmodel:php linksscope:lteversion:1.3

Trust: 0.8

sources: BID: 27529 // JVNDB: JVNDB-2008-002681 // CNNVD: CNNVD-200802-056 // NVD: CVE-2008-0566

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-0566
value: MEDIUM

Trust: 1.0

NVD: CVE-2008-0566
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200802-056
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2008-0566
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2008-002681 // CNNVD: CNNVD-200802-056 // NVD: CVE-2008-0566

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.8

sources: JVNDB: JVNDB-2008-002681 // NVD: CVE-2008-0566

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200802-056

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-200802-056

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-002681

PATCH

title:Top Pageurl:http://www.deltascripts.com/

Trust: 0.8

sources: JVNDB: JVNDB-2008-002681

EXTERNAL IDS

db:NVDid:CVE-2008-0566

Trust: 2.7

db:BIDid:27529

Trust: 1.9

db:EXPLOIT-DBid:5022

Trust: 1.6

db:JVNDBid:JVNDB-2008-002681

Trust: 0.8

db:MILW0RMid:5022

Trust: 0.6

db:CNNVDid:CNNVD-200802-056

Trust: 0.6

sources: BID: 27529 // JVNDB: JVNDB-2008-002681 // CNNVD: CNNVD-200802-056 // NVD: CVE-2008-0566

REFERENCES

url:http://www.securityfocus.com/bid/27529

Trust: 1.6

url:https://www.exploit-db.com/exploits/5022

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-0566

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-0566

Trust: 0.8

url:http://www.milw0rm.com/exploits/5022

Trust: 0.6

url:http://www.deltascripts.com/phplinks

Trust: 0.3

sources: BID: 27529 // JVNDB: JVNDB-2008-002681 // CNNVD: CNNVD-200802-056 // NVD: CVE-2008-0566

CREDITS

Houssamix from H-T Team discovered this issue.

Trust: 0.9

sources: BID: 27529 // CNNVD: CNNVD-200802-056

SOURCES

db:BIDid:27529
db:JVNDBid:JVNDB-2008-002681
db:CNNVDid:CNNVD-200802-056
db:NVDid:CVE-2008-0566

LAST UPDATE DATE

2025-04-10T23:13:06.602000+00:00


SOURCES UPDATE DATE

db:BIDid:27529date:2015-05-07T17:33:00
db:JVNDBid:JVNDB-2008-002681date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200802-056date:2008-09-05T00:00:00
db:NVDid:CVE-2008-0566date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:BIDid:27529date:2008-01-30T00:00:00
db:JVNDBid:JVNDB-2008-002681date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200802-056date:2008-02-04T00:00:00
db:NVDid:CVE-2008-0566date:2008-02-05T02:00:00