e107 eTrace Remote Command Execution Vulnerability
BID:13934
Info
e107 eTrace Remote Command Execution Vulnerability
| Bugtraq ID: | 13934 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1966 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to Oliver Monneke <[email protected]>. |
| Vulnerable: |
e107.org eTrace 1.0 2 e107.org eTrace 1.0 1 e107.org ePing 1.0 1 |
| Not Vulnerable: |
e107.org eTrace 1.0 3 |
Discussion
e107 eTrace Remote Command Execution Vulnerability
eTrace is prone to a remote command execution vulnerability.
Due to this, an attacker can supply arbitrary shell commands and have them executed in the context of the server. This can facilitate various attacks including unauthorized access to an affected computer.
eTrace is prone to a remote command execution vulnerability.
Due to this, an attacker can supply arbitrary shell commands and have them executed in the context of the server. This can facilitate various attacks including unauthorized access to an affected computer.
Exploit / POC
e107 eTrace Remote Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
e107 eTrace Remote Command Execution Vulnerability
Solution:
The vendor has released version 1.03 to address this issue:
e107.org eTrace 1.0 1
e107.org eTrace 1.0 2
Solution:
The vendor has released version 1.03 to address this issue:
e107.org eTrace 1.0 1
-
e107 eTrace 1.03
http://e107plugins.co.uk/request.php?6
e107.org eTrace 1.0 2
-
e107 eTrace 1.03
http://e107plugins.co.uk/request.php?6
References
e107 eTrace Remote Command Execution Vulnerability
References:
References:
- ePing Product Page (e107.org)
- eTrace Home Page (e107.org)
- New Etrace and Eping Versions 1.03 Available (e107plugins.co.uk)
- Re: Arbitrary code execution in eping plugin (Oliver Monneke
) - Vulnerability in ePing and eTrace plugins of e107 ([email protected])