« Volver al listado

CVE-2008-5920

Estado: ModificadaAlta (7.5)—

The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5920",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-01-21T02:30:00.297",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/4928",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gulftech.org/?node=research&article_id=00132-10202008",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/31891",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48168",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6822",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4928",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gulftech.org/?node=research&article_id=00132-10202008",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/31891",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48168",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6822",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch."
    },
    {
      "lang": "es",
      "value": "La función create_anchors en utils.inc en WebSVN v1.x permite a atacantes remotos ejecutar código PHP de su elección a través de nombres de usuario manipulados que es procesado por la función preg_replace con el switch \"eval\"."
    }
  ],
  "lastModified": "2026-06-16T23:01:13.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5184AC02-1F9D-4986-A08A-837A9CCA79D5"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE26E8A6-A516-4D1D-894D-E23AABA51A7F"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFDC8A10-08EB-4444-8771-4493E491DD21"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93B1AFDE-3DF3-4F9D-B6C9-54AD7F1F056C"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F420EE5-22E2-42B7-A906-EA9FEC4053DC"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31688948-CC90-46AA-AB3A-B66B88E465FE"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDBFBAEE-7B71-4D40-ACA1-BCFC889C0D04"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.31a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E889518B-485B-4CD3-996B-7198DFBAD805"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.32:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "648D1220-2387-497E-BBAE-82D43903754A"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AAF04A7-4D3C-4A56-99BA-3075D59DA136"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FF1A838-B8B8-4395-9317-8A6A2552C2D1"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E28A169D-4C20-42A5-9947-D996710D5705"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8BE03BE-1122-4A78-9E7C-9ADA01DCD8C0"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AEFAEA8-7A6E-430A-87DD-C6C9C55D5ABF"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07CF6D7C-8F68-47F3-BD5B-0720B33EB89D"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.51:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BC5AAC1-6110-4282-824C-6A660BEC5517"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.60:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C26622F-C77F-42AB-AA6A-F13B3A12DB7D"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.61:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D0152F8-71BA-4C7D-A8A1-72340B6924C4"
            },
            {
              "criteria": "cpe:2.3:a:tigris:websvn:1.62:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58024D23-C2D7-42E9-B0A2-7F774939241A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "Patch information - http://websvn.tigris.org/"
}