CVE-2009-0677
Estado: ModificadaMedia (6.5)—
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 9.03%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad
- http://secunia.com/advisories/33928
- http://www.osvdb.org/52007
- http://www.securityfocus.com/archive/1/500988/100/0/threaded
- http://www.securityfocus.com/bid/33787
- http://www.waraxe.us/advisory-72.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48789
- https://www.exploit-db.com/exploits/8068
- http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad
- http://secunia.com/advisories/33928
- http://www.osvdb.org/52007
- http://www.securityfocus.com/archive/1/500988/100/0/threaded
- http://www.securityfocus.com/bid/33787
- http://www.waraxe.us/advisory-72.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48789
- https://www.exploit-db.com/exploits/8068
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-0677",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-02-22T22:30:00.983",
"references": [
{
"url": "http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33928",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/52007",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/500988/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/33787",
"source": "cve@mitre.org"
},
{
"url": "http://www.waraxe.us/advisory-72.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48789",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/8068",
"source": "cve@mitre.org"
},
{
"url": "http://ravenphpscripts.com/postt17156.html&sid=12d1201371612260a42fa846ebce7bad",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/33928",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/52007",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/500988/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/33787",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.waraxe.us/advisory-72.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48789",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/8068",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array."
},
{
"lang": "es",
"value": "avatarlist.php en el módulo Your Account, alcanzado a traves de modules.php, en Raven Web Services RavenNuke v2.30 lo que permite a usuarios remotos autentificados ejecutar codigo a su eleccion a traves de secuencias PHP en un elemento del array de reemplazo, lo que es procesado por la funcion preg_replace con el interruptor de evaluacion, como se especifica en un elemento del array de patrones."
}
],
"lastModified": "2026-06-16T23:05:33.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ravenphpscripts:ravennuke:2.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24561E2B-3481-4E0C-8115-14A7FBB2F176"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}