CVE-2008-4796

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
30/10/2008
Last modified:
09/04/2025

Description

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snoopy_project:snoopy:*:*:*:*:*:*:*:* 1.2.3 (including)
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:* 4.2.2 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 2.6.3 (excluding)