VYPR
Unrated severityNVD Advisory· Published Oct 9, 2008· Updated Jun 16, 2026

CVE-2008-4529

CVE-2008-4529

Description

Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8) MemcachedStore.php, (9) Message.php, (10) Nonce.php, (11) SQLStore.php, (12) SReg.php, (13) TrustRoot.php, and (14) URINorm.php in classes/Auth/OpenID/; and (15) XRDS.php, (16) XRI.php and (17) XRIRes.php in classes/Auth/Yadis/.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Asicms/Asicms2 versions
    cpe:2.3:a:asicms:asicms:0.208:alpha:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:asicms:asicms:0.208:alpha:*:*:*:*:*:*
    • (no CPE)range: = alpha 0.208

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.