10
CVSSv2

CVE-2008-4304

Published: 23/12/2008 Updated: 08/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

general/login.php in phpCollab 2.5 rc3 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always has a base64-encoded string value, which may impose constraints on injection for typical shells.

Vulnerable Product Search on Vulmon Subscribe to Product

phpcollab phpcollab 2.5

phpcollab phpcollab

phpcollab phpcollab 2.4

phpcollab phpcollab 2.3

phpcollab phpcollab 2.2