CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
BID:14565
Info
CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
| Bugtraq ID: | 14565 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2005 12:00AM |
| Updated: | Aug 15 2005 12:00AM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
CPAINT CPAINT 1.3 |
| Not Vulnerable: |
CPAINT CPAINT 1.3 -SP |
Discussion
CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
CPAINT is affected by unspecified command execution and information disclosure vulnerabilities. These issues are most likely due to an access validation error.
Successful exploitation of these vulnerabilities could lead to a compromise of the server running the affected application. Information obtained may also aid in further attacks; other attacks are also possible.
CPAINT is affected by unspecified command execution and information disclosure vulnerabilities. These issues are most likely due to an access validation error.
Successful exploitation of these vulnerabilities could lead to a compromise of the server running the affected application. Information obtained may also aid in further attacks; other attacks are also possible.
Exploit / POC
CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
Solution:
The vendor has addressed this issue in the latest release of the software:
CPAINT CPAINT 1.3
Solution:
The vendor has addressed this issue in the latest release of the software:
CPAINT CPAINT 1.3
-
CPAINT cpaint-v1.3-SP.tar.gz
http://prdownloads.sourceforge.net/cpaint/cpaint-v1.3-SP.tar.gz?downlo ad
References
CPaint Unspecified Command Execution and Information Disclosure Vulnerabilities
References:
References: