CVE-2008-5090

N/A Unknown
Published: November 14, 2008 Modified: April 23, 2026
View on NVD

Description

Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/31978
Source: cve@mitre.org
Vendor Advisory
http://www.anelectron.com/board/index.php?tid=3282
Source: cve@mitre.org
Vendor Advisory
http://www.securityfocus.com/bid/31268
Source: cve@mitre.org
Exploit
http://secunia.com/advisories/31978
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securityreason.com/securityalert/4598
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.anelectron.com/board/index.php?tid=3282
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.gulftech.org/?node=research&article_id=00131-09202008
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/496552/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/31268
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/45270
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/6499
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
14.3%
94th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

anelectron