mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
98 lines
2.9 KiB
JSON
98 lines
2.9 KiB
JSON
{
|
|
"CVE_data_meta" : {
|
|
"ASSIGNER" : "cve@mitre.org",
|
|
"ID" : "CVE-2008-0506",
|
|
"STATE" : "PUBLIC"
|
|
},
|
|
"affects" : {
|
|
"vendor" : {
|
|
"vendor_data" : [
|
|
{
|
|
"product" : {
|
|
"product_data" : [
|
|
{
|
|
"product_name" : "n/a",
|
|
"version" : {
|
|
"version_data" : [
|
|
{
|
|
"version_value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format" : "MITRE",
|
|
"data_type" : "CVE",
|
|
"data_version" : "4.0",
|
|
"description" : {
|
|
"description_data" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php."
|
|
}
|
|
]
|
|
},
|
|
"problemtype" : {
|
|
"problemtype_data" : [
|
|
{
|
|
"description" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "n/a"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references" : {
|
|
"reference_data" : [
|
|
{
|
|
"name" : "20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14",
|
|
"refsource" : "BUGTRAQ",
|
|
"url" : "http://www.securityfocus.com/archive/1/487310/100/200/threaded"
|
|
},
|
|
{
|
|
"name" : "5019",
|
|
"refsource" : "EXPLOIT-DB",
|
|
"url" : "https://www.exploit-db.com/exploits/5019"
|
|
},
|
|
{
|
|
"name" : "http://www.waraxe.us/advisory-65.html",
|
|
"refsource" : "MISC",
|
|
"url" : "http://www.waraxe.us/advisory-65.html"
|
|
},
|
|
{
|
|
"name" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "http://coppermine-gallery.net/forum/index.php?topic=50103.0"
|
|
},
|
|
{
|
|
"name" : "27512",
|
|
"refsource" : "BID",
|
|
"url" : "http://www.securityfocus.com/bid/27512"
|
|
},
|
|
{
|
|
"name" : "1019286",
|
|
"refsource" : "SECTRACK",
|
|
"url" : "http://www.securitytracker.com/id?1019286"
|
|
},
|
|
{
|
|
"name" : "28682",
|
|
"refsource" : "SECUNIA",
|
|
"url" : "http://secunia.com/advisories/28682"
|
|
},
|
|
{
|
|
"name" : "ADV-2008-0367",
|
|
"refsource" : "VUPEN",
|
|
"url" : "http://www.vupen.com/english/advisories/2008/0367"
|
|
}
|
|
]
|
|
}
|
|
}
|