// For flags

CVE-2008-2041

Gentoo Linux Security Advisory 200805-4

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.

Múltiples vulnerabilidades no especificadas en eGroupWare anterior a 1.4.004, tienen vectores de ataque no especificados y un impacto "grave" cuando el servidor web tiene acceso de escritura a un directorio bajo la raíz de los documentos web.

A vulnerability has been reported in FCKEditor due to the way that file uploads are handled in the file editor/filemanager/upload/php/upload.php when a filename has multiple file extensions (CVE-2008-2041). Another vulnerability exists in the _bad_protocol_once() function in the file phpgwapi/inc/class.kses.inc.php, which allows remote attackers to bypass HTML filtering (CVE-2008-1502). Versions less than 1.4.004 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-04-30 CVE Reserved
  • 2008-04-30 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Egroupware
Search vendor "Egroupware"
Egroupware
Search vendor "Egroupware" for product "Egroupware"
<= 1.4.003
Search vendor "Egroupware" for product "Egroupware" and version " <= 1.4.003"
-
Affected
Egroupware
Search vendor "Egroupware"
Egroupware
Search vendor "Egroupware" for product "Egroupware"
1.4.001
Search vendor "Egroupware" for product "Egroupware" and version "1.4.001"
-
Affected
Egroupware
Search vendor "Egroupware"
Egroupware
Search vendor "Egroupware" for product "Egroupware"
1.4.002
Search vendor "Egroupware" for product "Egroupware" and version "1.4.002"
-
Affected