CVE-2008-4796
published 2008-10-30CVE-2008-4796: The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5)…
PriorityP353critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.98%
94.7th percentile
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libphp-snoopy | < libphp-snoopy 1.2.4-1 (bookworm) | libphp-snoopy 1.2.4-1 (bookworm) |
| debian | libphp-snoopy | < libphp-snoopy 2.0.0-1 (bookworm) | libphp-snoopy 2.0.0-1 (bookworm) |
| debian | wordpress | < libphp-snoopy 1.2.4-1 (bookworm) | libphp-snoopy 1.2.4-1 (bookworm) |
| nagios | nagios | < 4.2.2 | 4.2.2 |
| nagios | nagios | <= 4.2.1 | — |
| nagios | nagios | <= 4.2.3 | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| snoopy_project | snoopy | <= 1.2.3 | — |
| wordpress | wordpress | < 2.6.3 | 2.6.3 |
| wordpress | wordpress | >= 0 < 2.5.1-9 | 2.5.1-9 |
| wordpress | wordpress | >= 0 < 2.5.1-9 | 2.5.1-9 |
| wordpress | wordpress | >= 0 < 2.5.1-9 | 2.5.1-9 |
| wordpress | wordpress | >= 0 < 2.5.1-9 | 2.5.1-9 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wr36-qh3g-7h4v: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2008-7313 [CRITICAL] CWE-77 GHSA-wr36-qh3g-7h4v: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
GHSA
GHSA-828p-3vwg-wc22: MagpieRSS, as used in the front-end component in Nagios Core before 4
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2016-9565 [CRITICAL] CWE-284 GHSA-828p-3vwg-wc22: MagpieRSS, as used in the front-end component in Nagios Core before 4
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
GHSA
GHSA-g42h-8ph9-jmvx: The _httpsrequest function (Snoopy/Snoopy
ghsa_unreviewed·2022-05-13
CVE-2008-4796 [HIGH] CWE-78 GHSA-g42h-8ph9-jmvx: The _httpsrequest function (Snoopy/Snoopy
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
OSV
CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
osv·2017-03-31·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
OSV
CVE-2016-9565: MagpieRSS, as used in the front-end component in Nagios Core before 4
osv·2016-12-15·CVSS 10.0
CVE-2016-9565 [CRITICAL] CVE-2016-9565: MagpieRSS, as used in the front-end component in Nagios Core before 4
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
OSV
CVE-2008-4796: The _httpsrequest function (Snoopy/Snoopy
osv·2008-10-30·CVSS 10.0
CVE-2008-4796 [CRITICAL] CVE-2008-4796: The _httpsrequest function (Snoopy/Snoopy
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
Red Hat
nagios: Command injection via curl in MagpieRSS
vendor_redhat·2016-12-13·CVSS 10.0
CVE-2016-9565 [CRITICAL] CWE-77 nagios: Command injection via curl in MagpieRSS
nagios: Command injection via curl in MagpieRSS
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
It was found that an attacker who could control the content of an RSS feed could execute code remotely using the Nagios web interface. This flaw could be used to gain access to the remote system and in some scenarios control over the system.
Mitigation: #!/bin/bash
mv /usr/share/nagios/html/includes/rss /usr/share/nagios/html/includes/rss.disarmed
mv /usr/share/nagios/html/rss-corefeed.php /usr/share/nagios/html/rss-corefeed.php.disarmed
mv /usr/share/nagios/htm
Red Hat
snoopy: incomplete fixes for command execution flaws
vendor_redhat·2014-07-03·CVSS 10.0
CVE-2008-7313 [CRITICAL] snoopy: incomplete fixes for command execution flaws
snoopy: incomplete fixes for command execution flaws
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
Various command-execution flaws were found in the Snoopy library included with Nagios. These flaws allowed remote attackers to execute arbitrary commands by manipulating Nagios HTTP headers.
Package: nagios (Red Hat OpenStack Platform 3) - Will not fix
Package: nagios (Red Hat OpenStack Platform 4) - Will not fix
Package: nagios (Red Hat Storage 2.1) - Will not fix
Package: nagios (Red Hat Storage 3.0) - Will not fix
Ubuntu
Moodle vulnerabilities
vendor_ubuntu·2009-06-24·CVSS 6.8
CVE-2009-0500 [MEDIUM] Moodle vulnerabilities
Title: Moodle vulnerabilities
Summary: Moodle vulnerabilities
Thor Larholm discovered that PHPMailer, as used by Moodle, did not
correctly escape email addresses. A local attacker with direct access
to the Moodle database could exploit this to execute arbitrary commands
as the web server user. (CVE-2007-3215)
Nigel McNie discovered that fetching https URLs did not correctly escape
shell meta-characters. An authenticated remote attacker could execute
arbitrary commands as the web server user, if curl was installed and
configured. (CVE-2008-4796, MSA-09-0003)
It was discovered that Smarty (also included in Moodle), did not
correctly filter certain inputs. An authenticated remote attacker could
exploit this to execute arbitrary PHP commands as the web server user.
(CVE-2008-4810, CVE-2008
Red Hat
snoopy: command execution via shell metacharacters
vendor_redhat·2008-10-31·CVSS 10.0
CVE-2008-4796 [CRITICAL] CWE-78 snoopy: command execution via shell metacharacters
snoopy: command execution via shell metacharacters
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
Package: nagios (Red Hat Mobile Application Platform 4) - Will not fix
Debian
CVE-2008-4796: libphp-snoopy - The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier...
vendor_debian·2008·CVSS 10.0
CVE-2008-4796 [CRITICAL] CVE-2008-4796: libphp-snoopy - The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier...
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.
Scope: local
bookworm: resolved (fixed in 1.2.4-1)
bullseye: resolved (fixed in 1.2.4-1)
sid: resolved (fixed in 1.2.4-1)
Debian
CVE-2008-7313: libphp-snoopy - The _httpsrequest function in Snoopy allows remote attackers to execute arbitrar...
vendor_debian·2008·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313: libphp-snoopy - The _httpsrequest function in Snoopy allows remote attackers to execute arbitrar...
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
Scope: local
bookworm: resolved (fixed in 2.0.0-1)
bullseye: resolved (fixed in 2.0.0-1)
sid: resolved (fixed in 2.0.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9565 nagios: Command injection via curl in MagpieRSS
bugzilla·2016-12-16·CVSS 10.0
CVE-2016-9565 [CRITICAL] CVE-2016-9565 nagios: Command injection via curl in MagpieRSS
CVE-2016-9565 nagios: Command injection via curl in MagpieRSS
MagpieRSS, a component for handling RSS news feeds in Nagios Core control panel / front-end, was found vulnerable to command injection due to insufficient neutralization of special elements in function _httpsrequest().
The vulnerability could potentially enable remote unauthenticated attackers who managed to impersonate the feed server (via DNS poisoning, domain hijacking, ARP spoofing etc.), to provide a malicious response that injects parameters to curl command used by the affected RSS client class and effectively read/write arbitrary files on the vulnerable Nagios server. This could lead to Remote Code Execution in the context of www-data/nagios user on default Nagios installs that follow the official setup guidelines.
Thi
Bugzilla
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
bugzilla·2014-07-21·CVSS 10.0
CVE-2008-7313 [CRITICAL] CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-7313 CVE-2014-5008 CVE-2014-5009 snoopy: incomplete fixes for command execution flaws
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-
Bugzilla
CVE-2008-4796 snoopy: command execution via shell metacharacters [epel-6]
bugzilla·2013-04-30·CVSS 10.0
CVE-2008-4796 [CRITICAL] CVE-2008-4796 snoopy: command execution via shell metacharacters [epel-6]
CVE-2008-4796 snoopy: command execution via shell metacharacters [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for na
Bugzilla
CVE-2008-4796 snoopy: command execution via shell metacharacters [fedora-all]
bugzilla·2013-04-30·CVSS 10.0
CVE-2008-4796 [CRITICAL] CVE-2008-4796 snoopy: command execution via shell metacharacters [fedora-all]
CVE-2008-4796 snoopy: command execution via shell metacharacters [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2008-4796 snoopy: command execution via shell metacharacters
bugzilla·2008-10-31·CVSS 10.0
CVE-2008-4796 [CRITICAL] CVE-2008-4796 snoopy: command execution via shell metacharacters
CVE-2008-4796 snoopy: command execution via shell metacharacters
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4796 to the following vulnerability:
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3
and earlier allows remote attackers to execute arbitrary commands via
shell metacharacters in https URLs. NOTE: some of these details are
obtained from third party information.
References:
http://sourceforge.net/forum/forum.php?forum_id=879959
http://jvn.jp/en/jp/JVN20502807/index.html
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.html
http://www.frsirt.com/english/advisories/2008/2901
http://secunia.com/advisories/32361
Discussion:
Snoopy library is also included in WordPress. WordPress was fixed upstream in version 2.6.3:
http://wordpress
http://jvn.jp/en/jp/JVN20502807/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.htmlhttp://secunia.com/advisories/32361http://sourceforge.net/forum/forum.php?forum_id=879959http://www.debian.org/security/2008/dsa-1691http://www.debian.org/security/2009/dsa-1871http://www.openwall.com/lists/oss-security/2008/11/01/1http://www.securityfocus.com/archive/1/496068/100/0/threadedhttp://www.securityfocus.com/bid/31887http://www.vupen.com/english/advisories/2008/2901https://exchange.xforce.ibmcloud.com/vulnerabilities/46068https://security.gentoo.org/glsa/201702-26https://www.nagios.org/projects/nagios-core/history/4x/http://jvn.jp/en/jp/JVN20502807/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000074.htmlhttp://secunia.com/advisories/32361http://sourceforge.net/forum/forum.php?forum_id=879959http://www.debian.org/security/2008/dsa-1691http://www.debian.org/security/2009/dsa-1871http://www.openwall.com/lists/oss-security/2008/11/01/1http://www.securityfocus.com/archive/1/496068/100/0/threadedhttp://www.securityfocus.com/bid/31887http://www.vupen.com/english/advisories/2008/2901https://exchange.xforce.ibmcloud.com/vulnerabilities/46068https://security.gentoo.org/glsa/201702-26https://www.nagios.org/projects/nagios-core/history/4x/
2008-10-30
Published