CyberSec.Space Logo
返回 CVE 浏览器

CVE-2008-2886

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1930%
EPSS Percentile15.25th
Published2008年6月27日
Last Modified2026年4月23日

Vulnerability Description

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.

Affected Platforms (CPE)

📦
Jamroom

Jamroom

= 3.3.0
📦
Jamroom

Jamroom

= 3.3.1
📦
Jamroom

Jamroom

= 3.3.2
📦
Jamroom

Jamroom

= 3.3.3
📦
Jamroom

Jamroom

= 3.3.4
📦
Jamroom

Jamroom

= 3.3.5

References & Advisories

相关漏洞威胁