Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4796
Description:The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
Test IDs: 1.3.6.1.4.1.25623.1.0.860245   1.3.6.1.4.1.25623.1.0.63020   1.3.6.1.4.1.25623.1.0.860120   1.3.6.1.4.1.25623.1.0.61829   1.3.6.1.4.1.25623.1.0.860625   1.3.6.1.4.1.25623.1.0.61901   1.3.6.1.4.1.25623.1.0.860079   1.3.6.1.4.1.25623.1.0.61836   1.3.6.1.4.1.25623.1.0.63007   1.3.6.1.4.1.25623.1.0.61832   1.3.6.1.4.1.25623.1.0.61837   1.3.6.1.4.1.25623.1.0.61799   1.3.6.1.4.1.25623.1.0.106473   1.3.6.1.4.1.25623.1.0.64754   1.3.6.1.4.1.25623.1.0.860342   1.3.6.1.4.1.25623.1.0.860699   1.3.6.1.4.1.25623.1.0.64759  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4796
BugTraq ID: 31887
http://www.securityfocus.com/bid/31887
Bugtraq: 20080907 xoops-1.3.10 shell command execute vulnerability ( causing snoopy class ) (Google Search)
http://www.securityfocus.com/archive/1/496068/100/0/threaded
Debian Security Information: DSA-1691 (Google Search)
http://www.debian.org/security/2008/dsa-1691
Debian Security Information: DSA-1871 (Google Search)
http://www.debian.org/security/2009/dsa-1871
https://security.gentoo.org/glsa/201702-26
http://jvn.jp/en/jp/JVN20502807/index.html
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html
http://www.openwall.com/lists/oss-security/2008/11/01/1
http://secunia.com/advisories/32361
http://www.vupen.com/english/advisories/2008/2901
XForce ISS Database: snoopy-snoopyclass-command-execution(46068)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46068




© 1998-2025 E-Soft Inc. All rights reserved.