---
cve: "CVE-2008-5090"
severity: "LOW"
cvss: 3.1
epss: "4.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2008-11-14 19:20:53"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T10:02:48+02:00"
---

# CVE-2008-5090

> 3.1 LOW · 🧪 PoC

## Beschreibung

Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

## Exploit-Evidenz

- [EDB-6499 — Advanced Electron Forum 1.0.6 - Remote Code Execution](https://www.exploit-db.com/exploits/6499) ✅

## Referenzen

- <http://www.anelectron.com/board/index.php?tid=3282>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/45270>
- <http://www.securityfocus.com/archive/1/496552/100/0/threaded>
- <http://www.gulftech.org/?node=research&article_id=00131-09202008>
- <http://securityreason.com/securityalert/4598>
- <http://secunia.com/advisories/31978>
- <https://www.exploit-db.com/exploits/6499>
- <http://www.securityfocus.com/bid/31268>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-5090) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
