peter bassill · operator
$ cve CVE-2005-3330 JSON

CVE-2005-3330 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 17.2% (pctl 97)

Patch early

A public exploit exists.

Description

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS17.19% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2005-10-27
Last modified2026-06-16

Affected (1)

VendorProduct
snoopysnoopy

Public exploits

SourceTitleDate
exploit-dbSnoopy 0.9x/1.0/1.2 - Arbitrary Command Execution2005-10-26

References

→ the Explorer  ·  watch your stack  ·  NVD