Novell Forum Unspecified Tcl Command Injection Vulnerability
BID:30909
Info
Novell Forum Unspecified Tcl Command Injection Vulnerability
| Bugtraq ID: | 30909 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4047 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2008 12:00AM |
| Updated: | Apr 16 2015 05:55PM |
| Credit: | Novell |
| Vulnerable: |
Novell Forum 8.0 Novell Forum 7.3 Novell Forum 7.2 Novell Forum 7.1 Novell Forum 7.0 |
| Not Vulnerable: | |
Discussion
Novell Forum Unspecified Tcl Command Injection Vulnerability
Novell Forum is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the webserver process. Successful exploits could compromise the application and possibly the underlying system.
Novell Forum 8.0 and prior versions are affected by the issue.
Novell Forum is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the webserver process. Successful exploits could compromise the application and possibly the underlying system.
Novell Forum 8.0 and prior versions are affected by the issue.
Exploit / POC
Novell Forum Unspecified Tcl Command Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Novell Forum Unspecified Tcl Command Injection Vulnerability
Solution:
The vendor has released a fix. Please see the references for more information.
Novell Forum 7.0
Novell Forum 7.3
Novell Forum 7.2
Novell Forum 7.1
Novell Forum 8.0
Solution:
The vendor has released a fix. Please see the references for more information.
Novell Forum 7.0
Novell Forum 7.3
Novell Forum 7.2
Novell Forum 7.1
Novell Forum 8.0
References
Novell Forum Unspecified Tcl Command Injection Vulnerability
References:
References:
- Novell Forum Homepage (Novell)
- Security patch - Tcl Injection 6.0 - 7.x - 8.0 (Novell)