Plash Shell Command Injection Vulnerability
BID:22892
Info
Plash Shell Command Injection Vulnerability
| Bugtraq ID: | 22892 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-1400 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2007 12:00AM |
| Updated: | May 12 2015 07:33PM |
| Credit: | Mark Seaborn is credited with the discovery of this issue. |
| Vulnerable: |
Plash Plash 1.17 |
| Not Vulnerable: | |
Discussion
Plash Shell Command Injection Vulnerability
Plash is prone to a shell-command-injection vulnerability because the application fails to properly isolate executing binaries.
Successfully exploiting this issue allows attackers to escape the application's sandbox, potentially facilitating the remote compromise of targeted computers.
Plash version 1.17 is vulnerable to this issue; other versions may also be affected.
Plash is prone to a shell-command-injection vulnerability because the application fails to properly isolate executing binaries.
Successfully exploiting this issue allows attackers to escape the application's sandbox, potentially facilitating the remote compromise of targeted computers.
Plash version 1.17 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Plash Shell Command Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Plash Shell Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Plash Shell Command Injection Vulnerability
References:
References:
- [Plash] TTY ioctl() vulnerability (Mark Seaborn)
- Plash Home Page (Plash)
- Sandboxed process can send input to terminal (Plash)