FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
BID:14698
Info
FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
| Bugtraq ID: | 14698 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2005 12:00AM |
| Updated: | Aug 30 2005 12:00AM |
| Credit: | This issue was reported by JP Vendor Status Notes. |
| Vulnerable: |
FreeStyle Wiki Wiki 3.5.8 |
| Not Vulnerable: |
FreeStyle Wiki Wiki 3.5.9 |
Discussion
FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
FreeStyle Wiki is prone to an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary Perl commands in the context of the affected application.
FreeStyle Wiki is prone to an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary Perl commands in the context of the affected application.
Exploit / POC
FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
Solution:
The vendor has released version 3.5.9 to address this issue:
FreeStyle Wiki Wiki 3.5.8
Solution:
The vendor has released version 3.5.9 to address this issue:
FreeStyle Wiki Wiki 3.5.8
-
FreeStyle Wiki wiki3_5_9.zip
http://prdownloads.sourceforge.jp/fswiki/16170/wiki3_5_9.zip
References
FreeStyle Wiki Arbitrary Perl Command Execution Vulnerability
References:
References:
- FreeStyle Wiki 3.5.9 Advisory (FreeStyle Wiki)
- FreeStyle Wiki Homepage (FreeStyle Wiki)
- FreeStyle Wiki Wiki Forum (FreeStyle Wiki)
- JP Vendor Status Notes (JP Vendor)