Lucene search

K
cve[email protected]CVE-2008-2051
HistoryMay 05, 2008 - 5:20 p.m.

CVE-2008-2051

2008-05-0517:20:00
web.nvd.nist.gov
99
php
cve
escapeshellcmd
vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.3

Confidence

High

EPSS

0.02

Percentile

88.8%

The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to “incomplete multibyte chars.”

Affected configurations

NVD
Node
phpphpRange5.2.5
OR
phpphpMatch5.0.0beta1
OR
phpphpMatch5.0.0beta2
OR
phpphpMatch5.0.0beta3
OR
phpphpMatch5.0.0beta4
OR
phpphpMatch5.0.0rc1
OR
phpphpMatch5.0.0rc2
OR
phpphpMatch5.0.0rc3
OR
phpphpMatch5.0.1
OR
phpphpMatch5.0.2
OR
phpphpMatch5.0.3
OR
phpphpMatch5.0.4
OR
phpphpMatch5.0.5
OR
phpphpMatch5.1.0
OR
phpphpMatch5.1.1
OR
phpphpMatch5.1.2
OR
phpphpMatch5.1.3
OR
phpphpMatch5.1.4
OR
phpphpMatch5.1.5
OR
phpphpMatch5.1.6
OR
phpphpMatch5.2.0
OR
phpphpMatch5.2.1
OR
phpphpMatch5.2.2
OR
phpphpMatch5.2.3
OR
phpphpMatch5.2.4
VendorProductVersionCPE
phpphp5.2.3cpe:/a:php:php:5.2.3:::
phpphp5.0.0cpe:/a:php:php:5.0.0:beta1::
phpphpcpe:/a:php:php::::
phpphp5.0.0cpe:/a:php:php:5.0.0:rc2::
phpphp5.1.2cpe:/a:php:php:5.1.2:::
phpphp5.0.0cpe:/a:php:php:5.0.0:beta2::
phpphp5.0.0cpe:/a:php:php:5.0.0:beta4::
phpphp5.0.0cpe:/a:php:php:5.0.0:rc3::
phpphp5.0.2cpe:/a:php:php:5.0.2:::
phpphp5.2.4cpe:/a:php:php:5.2.4:::
Rows per page:
1-10 of 251

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.3

Confidence

High

EPSS

0.02

Percentile

88.8%