PT-2008-6006 · Ampache+6 · Ampache+6

Steffen Joeris

·

Publicado

2008-10-30

·

Atualizado

2024-06-15

·

CVE-2008-4796

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snoopy versions 1.2.3 and earlier ampache (affected versions not specified) libphp-snoopy (affected versions not specified) mahara (affected versions not specified) mediamate (affected versions not specified) opendb (affected versions not specified) pixelpost (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs, specifically through the httpsrequest function in Snoopy.
Recommendations For Snoopy versions 1.2.3 and earlier, update to a version later than 1.2.3 to resolve the issue. For ampache, consider disabling the httpsrequest function until a patch is available. For libphp-snoopy, restrict access to the httpsrequest function to minimize the risk of exploitation. For mahara, mediamate, opendb, and pixelpost, avoid using the httpsrequest function in Snoopy until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the other affected products.

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4796
DSA-1691-1
DSA-1871-1
DSA-1871-2
OPENSUSE-SU-2024:11073-1

Produtos afetados

Snoopy
Ampache
Libphp-Snoopy
Mahara
Mediamate
Opendb
Pixelpost