CVE-2008-2051: Critical severity php vulnerability
Published May 5, 2008
·Updated
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
Affected Software
25 affected components
PHP PHP=5.1.5
PHP PHP=5.1.2
PHP PHP=5.1.1
PHP PHP=5.0.0-beta1
PHP PHP=5.1.6
PHP PHP=5.2.2
PHP PHP=5.0.5
PHP PHP=5.0.1
PHP PHP=5.1.4
PHP PHP=5.0.4
PHP PHP=5.0.0-rc2
PHP PHP=5.2.3
PHP PHP=5.0.3
PHP PHP=5.1.0
PHP PHP=5.0.0-rc3
PHP PHP<=5.2.5
PHP PHP=5.2.0
PHP PHP=5.2.4
PHP PHP=5.0.0-beta3
PHP PHP=5.1.3
PHP PHP=5.0.0-rc1
PHP PHP=5.0.2
PHP PHP=5.2.1
PHP PHP=5.0.0-beta4
PHP PHP=5.0.0-beta2
Event History
May 5, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2051?
The severity of CVE-2008-2051 is currently classified as critical due to its impact on PHP versions prior to 5.2.6.
2
How do I fix CVE-2008-2051?
To fix CVE-2008-2051, upgrade your PHP installation to version 5.2.6 or later.
3
Which PHP versions are affected by CVE-2008-2051?
CVE-2008-2051 affects PHP versions 5.0.0 through 5.2.5, inclusive.
4
What vulnerabilities are associated with CVE-2008-2051?
CVE-2008-2051 is associated with issues arising from incomplete multibyte characters when using the escapeshellcmd function.
5
What are the potential impacts of CVE-2008-2051?
The potential impacts of CVE-2008-2051 include arbitrary command execution and security breaches depending on the attack vector.