CVE-2008-0892
UnknownEPSS 14.02%
Last modified
CVE-2008-0892 is a vulnerability of currently unknown severity. The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.. EPSS estimates a 14.02% chance of exploitation in the next 30 days.
Description
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Directory Server | 7.1 | — |
| Redhat | Directory Server | 8 | El4 |
| Redhat | Fedora Directory Server | All versions | — |
References
- http://secunia.com/advisories/29761Broken Link
- http://secunia.com/advisories/29826Broken Link
- http://secunia.com/advisories/30114Broken Link
- http://www.securityfocus.com/bid/28802Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019856Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=437301Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41840Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00380.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00386.htmlThird Party Advisory
- http://secunia.com/advisories/29761Broken Link
- http://secunia.com/advisories/29826Broken Link
- http://secunia.com/advisories/30114Broken Link
- http://www.securityfocus.com/bid/28802Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019856Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=437301Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41840Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00380.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00386.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0892?
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.
How severe is CVE-2008-0892?
Severity scoring for CVE-2008-0892 is pending analysis. The EPSS model estimates a 14.02% probability of exploitation in the next 30 days.
How do I fix CVE-2008-0892?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-0886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-0887gnome-screensaver before 2.22.1, when a remote authenticatio…
- CVE-2008-0888The NEEDBITS macro in the inflate_dynamic function in inflat…
- CVE-2008-0889Red Hat Directory Server 8.0, when running on Red Hat Enterp…
- CVE-2008-0890Red Hat Directory Server 7.1 before SP4 uses insecure permis…
- CVE-2008-0891Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when…
- CVE-2008-0893Red Hat Administration Server, as used by Red Hat Directory …
- CVE-2008-0894Apple Safari might allow remote attackers to obtain potentia…
- CVE-2008-0895BEA WebLogic Server and WebLogic Express 6.1 through 10.0 al…
- CVE-2008-0896BEA WebLogic Portal 10.0 and 9.2 through MP1, when an admini…
- CVE-2008-0897Unspecified vulnerability in BEA WebLogic Server 9.0 through…
- CVE-2008-0898The distributed queue feature in JMS in BEA WebLogic Server …
Are you affected by CVE-2008-0892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
