CVE-2008-4304
Published Dec 23, 2008
Last updated 7 years ago
Overview
- Description
- general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always has a base64-encoded string value, which may impose constraints on injection for typical shells.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-78
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpcollab:phpcollab:*:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "306A4BD2-EDA5-4C5C-9EDF-4A30002835C9", "versionEndIncluding": "2.5" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FEB4154-4FBA-439C-85B6-02EAAD97DCC2" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2E0172B-98CB-4777-A388-E9B0AB09A655" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82E3645C-2A9B-4F9D-B8FC-EFABB5550706" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.5:beta_4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D35D5533-5262-4A52-80E2-40A2AAC1F52F" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5C6C16C-9DC9-45C6-AA12-8A6B73F018ED" }, { "criteria": "cpe:2.3:a:phpcollab:phpcollab:2.5:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A23D06B-FB8A-42CC-B3B6-F720A2D892EE" } ], "operator": "OR" } ] } ]