CVE-2008-0932: Input Validation
Description of problem:
The Diatheke CGI allows arbitrary command execution in the context of the webserver, e.g. www-data by simply abusing the range parameter.
For example, &range=yes will consume tons of resources on the affected webserver. Escalation of privleges and command shells are left as an exercise to the reader.
From Debian: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466449
Other sources
diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0932?
CVE-2008-0932 is classified as a high severity vulnerability due to its potential for arbitrary command execution on the web server.
How do I fix CVE-2008-0932?
To fix CVE-2008-0932, update the affected versions of Diatheke CGI and the SWORD Project software to the latest secure versions.
Which software is affected by CVE-2008-0932?
CVE-2008-0932 affects versions of Diatheke Front End and Sword up to 1.5.9.
What type of vulnerability is CVE-2008-0932?
CVE-2008-0932 is a command injection vulnerability that allows an attacker to execute arbitrary commands on the server.
Can CVE-2008-0932 lead to privilege escalation?
Yes, CVE-2008-0932 can potentially lead to privilege escalation, allowing attackers to gain higher access rights on the affected server.