| Vulnerability Name: | CVE-2008-0893 (CCN-41843) | ||||||||
| Assigned: | 2008-04-15 | ||||||||
| Published: | 2008-04-15 | ||||||||
| Updated: | 2017-08-08 | ||||||||
| Summary: | Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions. | ||||||||
| CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-0893 Source: CCN Type: RHSA-2008-0201 Critical: redhat-ds-admin security update Source: CCN Type: SA29761 Red Hat update for redhat-ds-admin Source: SECUNIA Type: Vendor Advisory 29761 Source: SECUNIA Type: UNKNOWN 29826 Source: CCN Type: SECTRACK ID: 1019857 Red Hat Directory Server Lets Remote Users Access Administrative CGI Scripts Source: REDHAT Type: Patch RHSA-2008:0201 Source: BID Type: UNKNOWN 28802 Source: CCN Type: BID-28802 Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities Source: SECTRACK Type: UNKNOWN 1019857 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=437320 Source: XF Type: UNKNOWN rhds-cgiscripts-security-bypass(41843) Source: XF Type: UNKNOWN rhds-cgiscripts-security-bypass(41843) Source: FEDORA Type: UNKNOWN FEDORA-2008-3214 Source: FEDORA Type: UNKNOWN FEDORA-2008-3220 | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||