CVE-2008-5694
Last modified
CVE-2008-5694 is a vulnerability of currently unknown severity. PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the issue, if any, may be located in Aditus JpGraph rather than Sandbox. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the issue, if any, may be located in Aditus JpGraph rather than Sandbox. If so, then this should not be treated as an issue in Sandbox.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sandbox | Sandbox | 1.4.1 |
References
- http://www.by-f10.com/bug.txtURL Repurposed
- http://www.by-f10.com/bug.txtURL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5694?
How severe is CVE-2008-5694?
How do I fix CVE-2008-5694?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5688MediaWiki 1.8.1, and other versions before 1.13.3, when the …
- CVE-2008-5689tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 throug…
- CVE-2008-5690The Kerberos credential renewal feature in Sun Solaris 8, 9,…
- CVE-2008-5691Heap-based buffer overflow in the Phoenician Casino FlashAX …
- CVE-2008-5692Ipswitch WS_FTP Server Manager before 6.1.1, and possibly ot…
- CVE-2008-5693Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and poss…
- CVE-2008-5695wp-admin/options.php in WordPress MU before 1.3.2, and WordP…
- CVE-2008-5696Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux…
- CVE-2008-5697The skype_tool.copy_num method in the Skype extension BETA 2…
- CVE-2008-5698HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3…
- CVE-2008-5699The name service cache daemon (nscd) in Sun Solaris 10 and O…
- CVE-2008-5700libata in the Linux kernel before 2.6.27.9 does not set mini…
Are you affected by CVE-2008-5694?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
