CVE-2005-3330
Summary
| CVE | CVE-2005-3330 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-27 10:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - MagpieRSS Snoopy "_httpsrequest()" Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Ampache Snoopy "_httpsrequest()" Command Injection Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| SourceForge.net: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Snoopy Arbitrary Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| svn.ampache.org/branches/3.3.1/docs/CHANGELOG | af854a3a-2127-422b-91ae-364da2661108 | svn.ampache.org | |
| SecurityTracker.com Archives - Snoopy Input Validation Hole in _httpsrequest() Lets Remote Execute Arbitrary Commands | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Jinzora Snoopy "_httpsrequest()" Command Injection Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SourceForge.net: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Secunia - Advisories - Snoopy "_httpsrequest()" Shell Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.osvdb.org/20316 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.