The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-10-30T20:49:00

Updated: 2024-08-07T10:31:27.318Z

Reserved: 2008-10-30T00:00:00

Link: CVE-2008-4796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2008-10-30T20:56:54.770

Modified: 2021-09-30T15:13:22.947

Link: CVE-2008-4796

cve-icon Redhat

Severity : Important

Publid Date: 2008-10-31T00:00:00Z

Links: CVE-2008-4796 - Bugzilla