Chumby Multiple Products Remote Arbitrary Command Injection Vulnerability
BID:38771
Info
Chumby Multiple Products Remote Arbitrary Command Injection Vulnerability
| Bugtraq ID: | 38771 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0418 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2010 12:00AM |
| Updated: | Mar 16 2010 12:00AM |
| Credit: | Mark J Cox |
| Vulnerable: |
Chumby Industries Chumby One 1.0.3 Chumby Industries Chumby Classic 1.7.1 |
| Not Vulnerable: |
Chumby Industries Chumby One 1.0.4 Chumby Industries Chumby Classic 1.7.2 |
Discussion
Chumby Multiple Products Remote Arbitrary Command Injection Vulnerability
Multiple Chumby products are prone to a remote command-injection vulnerability because they fail to adequately sanitize user-supplied input data.
Remote attackers can exploit the issue to execute arbitrary shell commands.
Versions prior to Chumby One 1.0.4 and Chumby Classic 1.7.2 are vulnerable.
Multiple Chumby products are prone to a remote command-injection vulnerability because they fail to adequately sanitize user-supplied input data.
Remote attackers can exploit the issue to execute arbitrary shell commands.
Versions prior to Chumby One 1.0.4 and Chumby Classic 1.7.2 are vulnerable.
Solution / Fix
Chumby Multiple Products Remote Arbitrary Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.