Vulnerability record · CVE-2008-2689 · published 13 June 2008
CVE-2008-2689: BrowserCRM clients.php Remote File Inclusion Enables PHP Code Execution
BBrowsercrm · Browsercrm
BrowserCRM 5.002.00 contains a remote file inclusion flaw in pub/clients.php where the bcrm_pub_root parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause arbitrary PHP code to run on the server. The vulnerability is remotely reachable and requires no authentication.
Description
PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit references, and a high EPSS probability make this an urgent fix despite the absence of KEV listing.
What it is
BrowserCRM 5.002.00 contains a remote file inclusion flaw in pub/clients.php where the bcrm_pub_root parameter is used to include a remote file without validation. An attacker can point that parameter at a malicious URL and cause arbitrary PHP code to run on the server. The vulnerability is remotely reachable and requires no authentication.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which can lead to full compromise of the application and its data. The CVSS 2.0 vector rates confidentiality, integrity, and availability impact as complete.
Attack surface
The flaw is reached over the network through pub/clients.php by supplying a URL in the bcrm_pub_root parameter. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
The record is not listed in CISA KEV, but EPSS is high at 0.46188 (98.8th percentile) and references include an Exploit tag plus an Exploit-DB entry, indicating public exploit code exists.
What to do
- Apply the vendor fix for BrowserCRM 5.002.00 or upgrade to a version that validates the bcrm_pub_root parameter; if no patch is available, remove or disable pub/clients.php.
- Disable allow_url_include and allow_url_fopen in PHP to block remote file inclusion.
- Restrict outbound network access from the web server so it cannot fetch attacker-controlled URLs.
- Deploy a WAF rule that blocks URL-like values in bcrm_pub_root and similar parameters.
- Audit the web root for webshells or unexpected PHP files after any suspected exposure.
Detection
- Search web logs for requests to pub/clients.php with bcrm_pub_root containing http://, https://, ftp://, or other URL schemes.
- Monitor for outbound HTTP requests from the web server to unfamiliar external hosts.
- Alert on new or modified PHP files in the web root and on PHP processes spawning shell commands.
- Review PHP error logs for include or fopen failures referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2689 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2689), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.