AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-4304

HIGH · CVSS 10 EPSS 3.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-23 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 10.0. It may be remotely exploitable.

CVE
CVE-2008-4304
Severity
HIGH
CVSS
10
EPSS
3.01%

Original NVD Description

general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always has a base64-encoded string value, which may impose constraints on injection for typical shells.