CVE-2008-4318

Observer < 0.3.2.1 - Improper Input Validation

Title source: rule
STIX 2.1

Description

Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dun · textwebappsphp
https://www.exploit-db.com/exploits/6559

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6559
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4322
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45398

Scores

EPSS 0.0557
EPSS Percentile 90.3%

Details

CWE
CWE-20
Status published
Products (13)
project-observer/observer 0.1.0
project-observer/observer 0.1.1
project-observer/observer 0.1.2
project-observer/observer 0.2.0
project-observer/observer 0.2.1
project-observer/observer 0.2.2
project-observer/observer 0.2.3
project-observer/observer 0.2.4
project-observer/observer 0.2.5
project-observer/observer 0.3.1
... and 3 more
Published Sep 29, 2008
Tracked Since Feb 18, 2026