CVE-2008-4304
23.12.2008, 18:30
general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always has a base64-encoded string value, which may impose constraints on injection for typical shells.
Vendor | Product | Version |
---|---|---|
phpcollab | phpcollab | 𝑥 ≤ 2.5 |
phpcollab | phpcollab | 2.2 |
phpcollab | phpcollab | 2.3 |
phpcollab | phpcollab | 2.4 |
phpcollab | phpcollab | 2.5:beta_4 |
phpcollab | phpcollab | 2.5:rc1 |
phpcollab | phpcollab | 2.5:rc2 |
𝑥
= Vulnerable software versions
References