VDB
CVE-2008-1136
CVE-2008-1136
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679.
EPSS 8.71% · 92.6th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
8.71%
92.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| synce | synce | 0.10.0, 0.92 |
| n/a | n/a | n/a |
Timeline
- Mar 4, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- synce-vdccm-command-execution(39506) vdb
- 20080107 CORE-2007-1106: SynCE Remote Command Injection mailing-list
- http://www.coresecurity.com/?action=item&id=2070 url
- 27178 vdb
- 3710 third-party-advisory
- 29228 third-party-advisory
- 28141 vdb
- FEDORA-2008-0680 vendor-advisory
- http://sourceforge.net/forum/forum.php?forum_id=766440 url
- 29285 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-1136 advisory