First published: Thu Jan 15 2009(Updated: )
Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KTorrent | =2.0.3 | |
KTorrent | =1.1 | |
KTorrent | =3.0.2 | |
KTorrent | =3.1.2 | |
KTorrent | =2.2-beta1 | |
KTorrent | =2.0-rc1 | |
KTorrent | =2.2.1 | |
KTorrent | =2.2.8 | |
KTorrent | =2.1 | |
KTorrent | =2.2 | |
KTorrent | =2.1.1 | |
KTorrent | =2.2.2 | |
KTorrent | =2.2-rc1 | |
KTorrent | <=3.1.3 | |
KTorrent | =2.1.2 | |
KTorrent | =2.1-rc1 | |
KTorrent | =2.0.1 | |
KTorrent | =1.2-rc1 | |
KTorrent | =1.2-rc2 | |
KTorrent | =2.2.5 | |
KTorrent | =2.1.4 | |
KTorrent | =2.2.7 | |
KTorrent | =3.0-beta1 | |
KTorrent | =3.0.1 | |
KTorrent | =3.0.0 | |
KTorrent | =2.0 | |
KTorrent | =2.1-beta1 | |
KTorrent | =1.2 | |
KTorrent | =3.0-rc1 | |
KTorrent | =2.2.3 | |
KTorrent | =0.9 | |
KTorrent | =2.2.4 | |
KTorrent | =2.0-beta1 | |
KTorrent | =2.2.6 | |
KTorrent | =2.1.3 | |
KTorrent | =1.0 | |
KTorrent | =3.1.1 | |
KTorrent | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5906 has a high severity rating due to its potential to allow remote attackers to execute arbitrary PHP code.
To fix CVE-2008-5906, upgrade KTorrent to version 3.1.4 or later.
CVE-2008-5906 affects KTorrent versions below 3.1.4, including several earlier versions.
Yes, CVE-2008-5906 can lead to data compromise as it allows execution of arbitrary code by attackers.
While there are no specific public exploits reported for CVE-2008-5906, its nature makes it a significant risk to vulnerable systems.