Adobe Connect CVE-2018-4923 OS Command Injection Vulnerability
BID:103391
CVE-2018-4923 |Info
Adobe Connect CVE-2018-4923 OS Command Injection Vulnerability
| Bugtraq ID: | 103391 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-4923 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2018 12:00AM |
| Updated: | Mar 13 2018 12:00AM |
| Credit: | Rgod |
| Vulnerable: |
Adobe Connect 9.6.2 Adobe Connect 9.6.1 Adobe Connect 9.5.7 Adobe Connect 9.5.6 Adobe Connect 9.7 Adobe Connect 9.5.3 Adobe Connect 9.5.2 Adobe Connect 9.4.2 Adobe Connect 9.4 Adobe Connect 9.3 |
| Not Vulnerable: |
Adobe Connect 9.7.5 |
Discussion
Adobe Connect CVE-2018-4923 OS Command Injection Vulnerability
Adobe Connect is prone to an OS command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
Connect 9.7 and prior are vulnerable.
Adobe Connect is prone to an OS command-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
Connect 9.7 and prior are vulnerable.