Where
-Infinity
0

Vendor Risk Score

See how snoopy compares to other vendors in security performance

View Risk Score →
Severity
9.8
Command Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27

The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).

It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:

http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/

And fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28

This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).

However, the CVE-2014-5008 fix was also incomplete:

https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706

This was fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29

And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).

References:

http://www.openwall.com/lists/oss-security/2014/07/09/11

1 / 3
Source: Red Hat
First published (updated )
Severity
9.8
Command Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

1 / 2
First published (updated )
Severity
9.8
Command Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Snoopy allows remote attackers to execute arbitrary commands.

1 / 2
First published (updated )
Severity
7.5
Input Validation
AV:N/AC:L/Au:N/C:P/I:P/A:P

The httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

First published (updated )
Severity
7

CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27

The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).

It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:

http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/

And fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28

This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).

However, the CVE-2014-5008 fix was also incomplete:

https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706

This was fixed with the following:

http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29

And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).

References:

http://www.openwall.com/lists/oss-security/2014/07/09/11

First published (updated )
Severity
4.3
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in blocks/html/blockhtml.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

First published (updated )
Severity
4

Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4796 to the following vulnerability:

The httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs. NOTE: some of these details are obtained from third party information.

References: http://sourceforge.net/forum/forum.php?forumid=879959 http://jvn.jp/en/jp/JVN20502807/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html http://www.frsirt.com/english/advisories/2008/2901 http://secunia.com/advisories/32361

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203