dotDefender 'index1.cgi' Remote Command Execution Vulnerability
BID:40493
Info
dotDefender 'index1.cgi' Remote Command Execution Vulnerability
| Bugtraq ID: | 40493 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2009 12:00AM |
| Updated: | Nov 30 2009 12:00AM |
| Credit: | John Dos |
| Vulnerable: |
Applicure Technologies dotDefender 3.8-5 |
| Not Vulnerable: |
Applicure Technologies dotDefender 4.0 |
Discussion
dotDefender 'index1.cgi' Remote Command Execution Vulnerability
dotDefender is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected software and the underlying server.
dotDefender 3.8-5 and prior 3.x versions are vulnerable.
dotDefender is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected software and the underlying server.
dotDefender 3.8-5 and prior 3.x versions are vulnerable.
Exploit / POC
dotDefender 'index1.cgi' Remote Command Execution Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
dotDefender 'index1.cgi' Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Applicure Technologies dotDefender 3.8-5
Solution:
Updates are available. Please see the references for details.
Applicure Technologies dotDefender 3.8-5
-
Linux Remote Command Execution Vulnerability
http://www.applicure.com/downloads/misc/index1.tar.gz
References
dotDefender 'index1.cgi' Remote Command Execution Vulnerability
References:
References:
- dotDefender Homepage (Applicure Technologies)
- Linux Remote Command Execution Vulnerability (Applicure Technologies)
- Remote Command Execution in dotDefender Site Management (John Dos
)