// For flags

CVE-2008-2051

PHP multibyte shell escape flaw

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."

La funciĆ³n escapeshellcmd API en PHP anterior a 5.2.6 tiene impacto desconocido y vectores de ataque dependientes del contexto relacionados con "caracteres multibyte incompletos".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-05-02 CVE Reserved
  • 2008-05-05 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (45)
URL Tag Source
http://secunia.com/advisories/30048 Third Party Advisory
http://secunia.com/advisories/30083 Third Party Advisory
http://secunia.com/advisories/30158 Third Party Advisory
http://secunia.com/advisories/30288 Third Party Advisory
http://secunia.com/advisories/30345 Third Party Advisory
http://secunia.com/advisories/30411 Third Party Advisory
http://secunia.com/advisories/30757 Third Party Advisory
http://secunia.com/advisories/30828 Third Party Advisory
http://secunia.com/advisories/30967 Third Party Advisory
http://secunia.com/advisories/31119 Third Party Advisory
http://secunia.com/advisories/31124 Third Party Advisory
http://secunia.com/advisories/31200 Third Party Advisory
http://secunia.com/advisories/31326 Third Party Advisory
http://secunia.com/advisories/32746 Third Party Advisory
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176 X_refsource_confirm
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0178 X_refsource_confirm
http://www.openwall.com/lists/oss-security/2008/05/02/2 Mailing List
http://www.php.net/ChangeLog-5.php X_refsource_confirm
http://www.securityfocus.com/archive/1/492535/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/492671/100/0/threaded Mailing List
http://www.securityfocus.com/bid/29009 Vdb Entry
http://www.vupen.com/english/advisories/2008/1412 Vdb Entry
http://www.vupen.com/english/advisories/2008/2268 Vdb Entry
https://issues.rpath.com/browse/RPL-2503 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10256 Signature
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.2.5
Search vendor "Php" for product "Php" and version " <= 5.2.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.1
Search vendor "Php" for product "Php" and version "5.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.2
Search vendor "Php" for product "Php" and version "5.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.3
Search vendor "Php" for product "Php" and version "5.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.4
Search vendor "Php" for product "Php" and version "5.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.5
Search vendor "Php" for product "Php" and version "5.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.0
Search vendor "Php" for product "Php" and version "5.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.1
Search vendor "Php" for product "Php" and version "5.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.2
Search vendor "Php" for product "Php" and version "5.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.3
Search vendor "Php" for product "Php" and version "5.1.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.4
Search vendor "Php" for product "Php" and version "5.1.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.5
Search vendor "Php" for product "Php" and version "5.1.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.6
Search vendor "Php" for product "Php" and version "5.1.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.0
Search vendor "Php" for product "Php" and version "5.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.1
Search vendor "Php" for product "Php" and version "5.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.2
Search vendor "Php" for product "Php" and version "5.2.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.3
Search vendor "Php" for product "Php" and version "5.2.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.4
Search vendor "Php" for product "Php" and version "5.2.4"
-
Affected