peter bassill · operator
$ cve CVE-2008-4318 JSON

CVE-2008-4318 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 14.1% (pctl 96)

Patch early

A public exploit exists.

Description

Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS14.15% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-09-29
Last modified2026-06-16

Affected (1)

VendorProduct
project-observerobserver

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD