Vulnerability Description
PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is possible to manipulate gpg-keys or execute commands remotely. This attack appear to be exploitable via HKP-Api: /pks/lookup?search.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phkp Project | Phkp | All versions |
Related Weaknesses (CWE)
References
- https://tech.feedyourhead.at/content/full-disclosure-remote-command-execution-inExploitThird Party Advisory
- https://tech.feedyourhead.at/content/full-disclosure-remote-command-execution-inExploitThird Party Advisory
FAQ
What is CVE-2018-1000885?
CVE-2018-1000885 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec...
How severe is CVE-2018-1000885?
CVE-2018-1000885 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1000885?
Check the references section above for vendor advisories and patch information. Affected products include: Phkp Project Phkp.