Lucene search

K
cveMitreCVE-2008-2230
HistoryJun 11, 2008 - 1:32 a.m.

CVE-2008-2230

2008-06-1101:32:00
CWE-94
mitre
web.nvd.nist.gov
25
cve-2008-2230
untrusted search path
vulnerability
reportbug
reportbug-ng
arbitrary code execution

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.

Affected configurations

Nvd
Node
reportbug-ngreportbugMatch3.8
OR
reportbug-ngreportbugMatch3.31
OR
reportbug-ngreportbug-ngMatch0.2007.03.10
OR
reportbug-ngreportbug-ngMatch0.2007.03.11
OR
reportbug-ngreportbug-ngMatch0.2007.03.13
OR
reportbug-ngreportbug-ngMatch0.2007.03.14
OR
reportbug-ngreportbug-ngMatch0.2007.03.15
OR
reportbug-ngreportbug-ngMatch0.2007.03.17
OR
reportbug-ngreportbug-ngMatch0.2007.03.19
OR
reportbug-ngreportbug-ngMatch0.2007.03.19.2
OR
reportbug-ngreportbug-ngMatch0.2007.03.20
OR
reportbug-ngreportbug-ngMatch0.2007.03.24
OR
reportbug-ngreportbug-ngMatch0.2007.03.27
OR
reportbug-ngreportbug-ngMatch0.2007.03.28
OR
reportbug-ngreportbug-ngMatch0.2007.03.29
OR
reportbug-ngreportbug-ngMatch0.2007.04.07
OR
reportbug-ngreportbug-ngMatch0.2007.04.07.2
OR
reportbug-ngreportbug-ngMatch0.2007.04.13
OR
reportbug-ngreportbug-ngMatch0.2007.04.16
OR
reportbug-ngreportbug-ngMatch0.2007.04.20
OR
reportbug-ngreportbug-ngMatch0.2007.04.23
OR
reportbug-ngreportbug-ngMatch0.2007.04.27
OR
reportbug-ngreportbug-ngMatch0.2007.05.02
OR
reportbug-ngreportbug-ngMatch0.2007.05.27
OR
reportbug-ngreportbug-ngMatch0.2007.05.28
OR
reportbug-ngreportbug-ngMatch0.2007.05.31
OR
reportbug-ngreportbug-ngMatch0.2007.06.13
OR
reportbug-ngreportbug-ngMatch0.2007.06.27
OR
reportbug-ngreportbug-ngMatch0.2007.07.08
OR
reportbug-ngreportbug-ngMatch0.2007.07.12
OR
reportbug-ngreportbug-ngMatch0.2007.07.18
OR
reportbug-ngreportbug-ngMatch0.2007.07.19
OR
reportbug-ngreportbug-ngMatch0.2007.08.02
OR
reportbug-ngreportbug-ngMatch0.2007.08.03
OR
reportbug-ngreportbug-ngMatch0.2007.08.03.2
OR
reportbug-ngreportbug-ngMatch0.2007.08.12
OR
reportbug-ngreportbug-ngMatch0.2007.08.20
OR
reportbug-ngreportbug-ngMatch0.2007.10.30
OR
reportbug-ngreportbug-ngMatch0.2008.01.20
OR
reportbug-ngreportbug-ngMatch0.2008.03.26
OR
reportbug-ngreportbug-ngMatch0.2008.03.28
VendorProductVersionCPE
reportbug-ngreportbug3.8cpe:2.3:a:reportbug-ng:reportbug:3.8:*:*:*:*:*:*:*
reportbug-ngreportbug3.31cpe:2.3:a:reportbug-ng:reportbug:3.31:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.10cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.10:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.11cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.11:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.13cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.13:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.14cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.14:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.15cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.15:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.17cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.17:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.19cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.19:*:*:*:*:*:*:*
reportbug-ngreportbug-ng0.2007.03.19.2cpe:2.3:a:reportbug-ng:reportbug-ng:0.2007.03.19.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 411

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0

Percentile

5.1%