### [CVE-2008-7183](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7183) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description PHP remote file inclusion vulnerability in eva/index.php in EVA CMS 2.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the eva[caminho] parameter to index.php. ### POC #### Reference - http://packetstorm.linuxsecurity.com/0806-exploits/evacms-rfi.txt #### Github No PoCs found on GitHub currently.