Vulnerability Description
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | <= 5.2.5 |
References
- http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
- http://secunia.com/advisories/30048
- http://secunia.com/advisories/30083
- http://secunia.com/advisories/30158
- http://secunia.com/advisories/30288
- http://secunia.com/advisories/30345
- http://secunia.com/advisories/30411
- http://secunia.com/advisories/30757
- http://secunia.com/advisories/30828
- http://secunia.com/advisories/30967
- http://secunia.com/advisories/31119
- http://secunia.com/advisories/31124
- http://secunia.com/advisories/31200
- http://secunia.com/advisories/31326
FAQ
What is CVE-2008-2051?
CVE-2008-2051 is a vulnerability with a CVSS score of 10.0 (HIGH). The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
How severe is CVE-2008-2051?
CVE-2008-2051 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-2051?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php.