SWORD Remote Arbitrary Command Execution Vulnerability
BID:27874
Info
SWORD Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 27874 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0932 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Discovered by Dan Dennison <[email protected]>. |
| Vulnerable: |
The SWORD Project SWORD 1.5.10 The SWORD Project SWORD 1.5.9 |
| Not Vulnerable: | |
Discussion
SWORD Remote Arbitrary Command Execution Vulnerability
SWORD is prone to a remote command-execution vulnerability.
Successful exploits can allow arbitrary commands to run in the context of the affected application.
SWORD 1.5.10 and 1.5.9 are reported vulnerable; other versions may be affected as well.
SWORD is prone to a remote command-execution vulnerability.
Successful exploits can allow arbitrary commands to run in the context of the affected application.
SWORD 1.5.10 and 1.5.9 are reported vulnerable; other versions may be affected as well.
Exploit / POC
SWORD Remote Arbitrary Command Execution Vulnerability
An attacker can use a browser to carry out this attack.
An attacker can use a browser to carry out this attack.
Solution / Fix
SWORD Remote Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SWORD Remote Arbitrary Command Execution Vulnerability
References:
References:
- Debian Bug report logs - #466449 (Dan Dennison
) - Vendor Homepage (The SWORD Project)