Michael Barretto CardBoard Remote Command Execution Vulnerability
BID:3360
Info
Michael Barretto CardBoard Remote Command Execution Vulnerability
| Bugtraq ID: | 3360 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2001 12:00AM |
| Updated: | Sep 25 2001 12:00AM |
| Credit: | Discovered by Crazy Einstein <[email protected]> on Sep 25, 2001. |
| Vulnerable: |
Michael Barretto CardBoard 2.4 |
| Not Vulnerable: | |
Discussion
Michael Barretto CardBoard Remote Command Execution Vulnerability
CardBoard is an application used to send out e-greeting cards, and is maintained by Michael Barretto.
Due to the improper filtering of certain types of user-supplied input, it is possible for a user to submit a greeting card which causes arbitrary commands to be executed on the host with privileges of the server.
* Reproduction of this issue has not been successful.
CardBoard is an application used to send out e-greeting cards, and is maintained by Michael Barretto.
Due to the improper filtering of certain types of user-supplied input, it is possible for a user to submit a greeting card which causes arbitrary commands to be executed on the host with privileges of the server.
* Reproduction of this issue has not been successful.
Exploit / POC
Michael Barretto CardBoard Remote Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Michael Barretto CardBoard Remote Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Michael Barretto CardBoard Remote Command Execution Vulnerability
References:
References:
- CardBoard Homepage (Michael Barretto)