e107 ePing Remote Command Execution Vulnerability
BID:13929
Info
e107 ePing Remote Command Execution Vulnerability
| Bugtraq ID: | 13929 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2005 12:00AM |
| Updated: | Jun 10 2005 12:00AM |
| Credit: | Discovery is credited to m00fd1. |
| Vulnerable: |
e107.org ePing 1.0 2 e107.org ePing 1.0 1 |
| Not Vulnerable: |
e107.org ePing 1.0 3 |
Discussion
e107 ePing Remote Command Execution Vulnerability
ePing is prone to a remote command execution vulnerability.
Due to this, an attacker can supply arbitrary shell commands and have them executed in the context of the server. This can facilitate various attacks including unauthorized access to an affected computer.
ePing is prone to a remote command execution vulnerability.
Due to this, an attacker can supply arbitrary shell commands and have them executed in the context of the server. This can facilitate various attacks including unauthorized access to an affected computer.
Exploit / POC
e107 ePing Remote Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
e107 ePing Remote Command Execution Vulnerability
Solution:
The vendor has released version 1.03 to address this issue:
e107.org ePing 1.0 2
e107.org ePing 1.0 1
Solution:
The vendor has released version 1.03 to address this issue:
e107.org ePing 1.0 2
-
e107 ePing 1.03
http://e107plugins.co.uk/request.php?5
e107.org ePing 1.0 1
-
e107 ePing 1.03
http://e107plugins.co.uk/request.php?5
References
e107 ePing Remote Command Execution Vulnerability
References:
References:
- ePing Product Page (e107.org)
- New Etrace and Eping Versions 1.03 Available (e107plugins.co.uk)
- Re: Arbitrary code execution in eping plugin (Oliver Monneke
) - Vulnerability in ePing and eTrace plugins of e107 ([email protected])