First published: Thu Sep 11 2008(Updated: )
Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Novell Forum | =7.1 | |
Novell Novell Forum | =7.3 | |
Novell Novell Forum | =7.2 | |
Novell Novell Forum | =8.0 | |
Novell Novell Forum | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4047 has not been assigned a specific severity rating, but it allows remote attackers to execute arbitrary TCL code, which poses a significant security risk.
To fix CVE-2008-4047, you should upgrade Novell Forum to a later version that addresses this vulnerability.
CVE-2008-4047 affects Novell Forum versions 7.0, 7.1, 7.2, 7.3, and 8.0.
CVE-2008-4047 facilitates remote code execution attacks through crafted URLs.
Currently, there are no known effective workarounds for CVE-2008-4047; upgrading to a secure version is the recommended approach.