Vulnerability record · CVE-2008-5764 · published 30 December 2008
CVE-2008-5764: WorkSimple calendar.php lang parameter remote file inclusion
22500mhz · Worksimple
WorkSimple 1.2.1 contains a PHP remote file inclusion flaw in calendar.php. When register_globals is enabled, the lang parameter can be set to a remote URL, causing the application to include and execute attacker-supplied PHP code. This matters because it yields remote code execution on the web server with no authentication required.
Description
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote code execution with a high EPSS score and public exploit references, though exploitation requires register_globals to be enabled.
What it is
WorkSimple 1.2.1 contains a PHP remote file inclusion flaw in calendar.php. When register_globals is enabled, the lang parameter can be set to a remote URL, causing the application to include and execute attacker-supplied PHP code. This matters because it yields remote code execution on the web server with no authentication required.
Impact
An unauthenticated attacker can execute arbitrary PHP code on the server, leading to full compromise of the web application and potentially the underlying host.
Attack surface
Reachable over the network through HTTP requests to calendar.php with a crafted lang parameter. No authentication or user interaction is needed, but exploitation depends on the PHP register_globals setting being enabled.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.45 (98.7th percentile) and public exploit references exist, including an Exploit-DB entry and a SecurityFocus BID tagged Exploit.
What to do
- Upgrade or remove WorkSimple 1.2.1; no fixed version is stated in the record, so treat the product as unsupported and migrate off it.
- Disable register_globals in PHP configuration, which the record identifies as a precondition for exploitation.
- Restrict PHP allow_url_include and allow_url_fopen so remote URLs cannot be included.
- Deploy a WAF rule blocking URL values in the lang parameter and other file-inclusion style parameters.
- Isolate the web server with least privilege and network segmentation to limit post-exploitation reach.
Detection
- Monitor web logs for requests to calendar.php with lang parameters containing http:// or https:// URLs.
- Alert on PHP include or require errors referencing remote hosts in application error logs.
- Hunt for unexpected PHP files or outbound HTTP requests originating from the web server process.
- Review PHP configuration baselines for register_globals and allow_url_include being enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-5764 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5764), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.