CVE-2008-0148

Publication date 9 January 2008

Last updated 24 July 2024


Ubuntu priority

Description

TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.

Read the notes from the security team

Status

Package Ubuntu Release Status
tutos2 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

per Debian, not affected (vulnerable code not present)


Access our resources on patching vulnerabilities