PT-2008-6006 · Ampache+6 · Ampache+6

Steffen Joeris

·

Published

2008-10-30

·

Updated

2024-06-15

·

CVE-2008-4796

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snoopy versions 1.2.3 and earlier ampache (affected versions not specified) libphp-snoopy (affected versions not specified) mahara (affected versions not specified) mediamate (affected versions not specified) opendb (affected versions not specified) pixelpost (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs, specifically through the httpsrequest function in Snoopy.
Recommendations For Snoopy versions 1.2.3 and earlier, update to a version later than 1.2.3 to resolve the issue. For ampache, consider disabling the httpsrequest function until a patch is available. For libphp-snoopy, restrict access to the httpsrequest function to minimize the risk of exploitation. For mahara, mediamate, opendb, and pixelpost, avoid using the httpsrequest function in Snoopy until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the other affected products.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4796
DSA-1691-1
DSA-1871-1
DSA-1871-2
OPENSUSE-SU-2024:11073-1

Affected Products

Snoopy
Ampache
Libphp-Snoopy
Mahara
Mediamate
Opendb
Pixelpost