6.8

CVE-2008-5906

Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ktorrent ≫ Ktorrent Version <= 3.1.3
Ktorrent ≫ Ktorrent Version 0.9
Ktorrent ≫ Ktorrent Version 1.0
Ktorrent ≫ Ktorrent Version 1.1
Ktorrent ≫ Ktorrent Version 1.2
Ktorrent ≫ Ktorrent Version 1.2 Update rc1
Ktorrent ≫ Ktorrent Version 1.2 Update rc2
Ktorrent ≫ Ktorrent Version 2.0
Ktorrent ≫ Ktorrent Version 2.0 Update beta1
Ktorrent ≫ Ktorrent Version 2.0 Update rc1
Ktorrent ≫ Ktorrent Version 2.0.1
Ktorrent ≫ Ktorrent Version 2.0.2
Ktorrent ≫ Ktorrent Version 2.0.3
Ktorrent ≫ Ktorrent Version 2.1
Ktorrent ≫ Ktorrent Version 2.1 Update beta1
Ktorrent ≫ Ktorrent Version 2.1 Update rc1
Ktorrent ≫ Ktorrent Version 2.1.1
Ktorrent ≫ Ktorrent Version 2.1.2
Ktorrent ≫ Ktorrent Version 2.1.3
Ktorrent ≫ Ktorrent Version 2.1.4
Ktorrent ≫ Ktorrent Version 2.2
Ktorrent ≫ Ktorrent Version 2.2 Update beta1
Ktorrent ≫ Ktorrent Version 2.2 Update rc1
Ktorrent ≫ Ktorrent Version 2.2.1
Ktorrent ≫ Ktorrent Version 2.2.2
Ktorrent ≫ Ktorrent Version 2.2.3
Ktorrent ≫ Ktorrent Version 2.2.4
Ktorrent ≫ Ktorrent Version 2.2.5
Ktorrent ≫ Ktorrent Version 2.2.6
Ktorrent ≫ Ktorrent Version 2.2.7
Ktorrent ≫ Ktorrent Version 2.2.8
Ktorrent ≫ Ktorrent Version 3.0 Update beta1
Ktorrent ≫ Ktorrent Version 3.0 Update rc1
Ktorrent ≫ Ktorrent Version 3.0.0
Ktorrent ≫ Ktorrent Version 3.0.1
Ktorrent ≫ Ktorrent Version 3.0.2
Ktorrent ≫ Ktorrent Version 3.1.1
Ktorrent ≫ Ktorrent Version 3.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504178
http://ktorrent.org/?q=node/23
Vendor Advisory
http://openwall.com/lists/oss-security/2009/01/08/1
http://secunia.com/advisories/32442
Vendor Advisory
http://secunia.com/advisories/32447
Vendor Advisory
http://secunia.com/advisories/33675
http://secunia.com/advisories/34003
http://security.gentoo.org/glsa/glsa-200902-05.xml
http://www.securityfocus.com/bid/31927
http://www.ubuntu.com/usn/USN-711-1
http://www.vupen.com/english/advisories/2008/2911
https://bugs.gentoo.org/show_bug.cgi?id=244741
https://exchange.xforce.ibmcloud.com/vulnerabilities/46118