Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
BID:14299
Info
Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
| Bugtraq ID: | 14299 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 18 2005 12:00AM |
| Credit: | evy pk <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Y.SAK Y.SAK Scripts |
| Not Vulnerable: | |
Discussion
Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
Y.SAK Scripts are prone to multiple remote command execution vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. These issues arise when user-specified data is supplied to the Perl open() routine without proper sanitation.
Successful exploitation of any of these issues may facilitate unauthorized remote access in the context of the Web server to the affected computer.
Y.SAK Scripts are prone to multiple remote command execution vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. These issues arise when user-specified data is supplied to the Perl open() routine without proper sanitation.
Successful exploitation of any of these issues may facilitate unauthorized remote access in the context of the Web server to the affected computer.
Exploit / POC
Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Y.SAK Scripts Multiple Remote Arbitrary Command Execution Vulnerabilities
References:
References:
- Y.SAK Scripts Homepage (Y.SAK)