The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
BID:27987
Info
The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 27987 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0932 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2008 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | Dan Dennison discovered this issue. |
| Vulnerable: |
The SWORD Project SWORD 1.5.9 Red Hat Fedora 7 Gentoo Linux Diatheke Diatheke 1.5.9 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
The SWORD Project's Diatheke front-end is prone to a vulnerability that can allow arbitrary shell commands to run.
Successful exploits will compromise the application and possibly the underlying webserver.
SWORD 1.5.9 is vulnerable; other versions may also be affected.
The SWORD Project's Diatheke front-end is prone to a vulnerability that can allow arbitrary shell commands to run.
Successful exploits will compromise the application and possibly the underlying webserver.
SWORD 1.5.9 is vulnerable; other versions may also be affected.
Exploit / POC
The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
Solution:
Fixes to address this issue are available. Please see the references for more information.
Solution:
Fixes to address this issue are available. Please see the references for more information.
References
The SWORD Project Diatheke Unspecified Remote Command Execution Vulnerability
References:
References:
- Vendor Homepage (The SWORD Project)