CVE-2008-0893
Summary
| CVE | CVE-2008-0893 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-04-16 18:05:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Directory Server | 8.0 | el4 | All | All |
| Application | Redhat | Directory Server | 8.0 | el5 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 437320 – CVE-2008-0893 Directory Server: unrestricted access to CGI scripts | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Fedora update for fedora-ds-admin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Red Hat update for redhat-ds-admin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 7 Update: fedora-ds-admin-1.1.4-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch |
| Red Hat Directory Server Lets Remote Users Access Administrative CGI Scripts - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [SECURITY] Fedora 8 Update: fedora-ds-admin-1.1.4-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.