Lucene search

K
cve[email protected]CVE-2008-4796
HistoryOct 30, 2008 - 8:56 p.m.

CVE-2008-4796

2008-10-3020:56:54
CWE-78
web.nvd.nist.gov
51
cve
2008
4796
snoopy
snoopy.class.php
vulnerability
remote execution
shell metacharacters
security

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.1 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.6%

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

Affected configurations

NVD
Node
snoopy_projectsnoopyRange1.2.3
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
Node
nagiosnagiosRange<4.2.2
Node
wordpresswordpressRange<2.6.3

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.1 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.6%