CVE-2008-2888 describes multiple remote file inclusion vulnerabilities in MiGCMS version 2.0.5, specifically within collection.class.php and content_image.class.php, when the register_globals PHP setting is enabled. This critical vulnerability, rated with a CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary PHP code on affected systems by manipulating the GLOBALS[application][app_root] parameter. While there is no evidence of active exploitation in the wild or inclusion in CISA's KEV catalog, public exploit code is available via ExploitDB (EDB-5901), indicating a clear path for potential attackers. Despite its high severity and exploit availability, the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.5CPE matchmatch criteria | cpe:2.3:a:migcms:migcms:2.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.