HIGH · 10.0

CVE-2008-4796

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other pr...

Vulnerability Description

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Snoopy ProjectSnoopy<= 1.2.3
DebianDebian Linux4.0
NagiosNagios< 4.2.2
WordpressWordpress< 2.6.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-4796?

CVE-2008-4796 is a vulnerability with a CVSS score of 10.0 (HIGH). The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other pr...

How severe is CVE-2008-4796?

CVE-2008-4796 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-4796?

Check the references section above for vendor advisories and patch information. Affected products include: Snoopy Project Snoopy, Debian Debian Linux, Nagios Nagios, Wordpress Wordpress.