REDHAT-BUG-469320: Medium severity snoopy project snoopy vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4796 to the following vulnerability:
The httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs. NOTE: some of these details are obtained from third party information.
References: http://sourceforge.net/forum/forum.php?forumid=879959 http://jvn.jp/en/jp/JVN20502807/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html http://www.frsirt.com/english/advisories/2008/2901 http://secunia.com/advisories/32361
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-469320?
REDHAT-BUG-469320 is classified with a high severity due to the potential for remote code execution.
How do I fix REDHAT-BUG-469320?
To mitigate REDHAT-BUG-469320, upgrade Snoopy to version 1.2.4 or later.
What vulnerabilities does REDHAT-BUG-469320 address?
REDHAT-BUG-469320 addresses a remote code execution vulnerability found in the _httpsrequest function of Snoopy 1.2.3 and earlier.
Who is affected by REDHAT-BUG-469320?
Any system using Snoopy version 1.2.3 or earlier is affected by REDHAT-BUG-469320.
What can happen if REDHAT-BUG-469320 is exploited?
If exploited, REDHAT-BUG-469320 allows attackers to execute arbitrary code on the vulnerable system.