CVE-2008-4529 describes multiple remote file inclusion (RFI) vulnerabilities in asiCMS alpha 0.208, allowing remote attackers to execute arbitrary PHP code. This critical vulnerability, rated 7.5 CVSS, arises from improper handling of the _ENV[asicms][path] parameter across numerous PHP files within the Auth/OpenID and Auth/Yadis components. Successful exploitation could lead to full compromise of the affected system, including data theft, modification, and denial of service. While not listed on the KEV catalog and with no recorded active exploitation, public exploit code (EDB-6685) exists, and its high FAUCET Risk Score of 90/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.208CPE matchmatch criteria | cpe:2.3:a:asicms:asicms:0.208:alpha:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.