CVE-2008-5186

Source
https://nvd.nist.gov/vuln/detail/CVE-2008-5186
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2008-5186.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2008-5186
Downstream
Withdrawn
2017-08-07T12:57:01Z
Published
2008-11-21T02:30:00Z
Modified
2025-04-09T00:30:58Z
Summary
[none]
Details

The setlanguagepath function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate CVE identifiers would be created for web applications that integrate GeSHi in a way that allows control of the default language path

References

Affected packages

Debian:11 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.20080505-3.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.20080505-3.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.20080505-3.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / geshi

Package

Name
geshi
Purl
pkg:deb/debian/geshi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.8.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / geshi

Package

Name
geshi
Purl
pkg:deb/debian/geshi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.8.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / geshi

Package

Name
geshi
Purl
pkg:deb/debian/geshi?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.8.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}