CVE-2008-4796: OS Command Injection
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4796 to the following vulnerability:
The httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs. NOTE: some of these details are obtained from third party information.
References: http://sourceforge.net/forum/forum.php?forumid=879959 http://jvn.jp/en/jp/JVN20502807/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html http://www.frsirt.com/english/advisories/2008/2901 http://secunia.com/advisories/32361
Other sources
The httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4796?
CVE-2008-4796 is classified as a high severity vulnerability due to its ability to allow remote command execution.
How do I fix CVE-2008-4796?
To fix CVE-2008-4796, you should upgrade Snoopy to version 1.2.4 or a later version, which addresses this vulnerability.
Which software is affected by CVE-2008-4796?
CVE-2008-4796 affects Snoopy versions up to and including 1.2.3, along with applications like Ampache, Nagios, and WordPress versions up to 2.6.3.
What types of attacks can exploit CVE-2008-4796?
CVE-2008-4796 can be exploited through remote command injection attacks via specially crafted HTTPS URLs.
Is CVE-2008-4796 still relevant today?
Yes, CVE-2008-4796 remains relevant for legacy systems and applications still using the vulnerable versions of the software.