pidgin-knotify 'notify()' Remote Command Injection Vulnerability
BID:43206
Info
pidgin-knotify 'notify()' Remote Command Injection Vulnerability
| Bugtraq ID: | 43206 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3088 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2010 12:00AM |
| Updated: | Mar 04 2014 03:01AM |
| Credit: | Matthias Petschick |
| Vulnerable: |
pidgin-knotify Pidgin-knotify 0.2.1 |
| Not Vulnerable: | |
Discussion
pidgin-knotify 'notify()' Remote Command Injection Vulnerability
pidgin-knotify is prone to a command-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
pidgin-knotify 0.2.1 is affected; other versions may also be vulnerable.
pidgin-knotify is prone to a command-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
pidgin-knotify 0.2.1 is affected; other versions may also be vulnerable.
Exploit / POC
pidgin-knotify 'notify()' Remote Command Injection Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
pidgin-knotify 'notify()' Remote Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
pidgin-knotify 'notify()' Remote Command Injection Vulnerability
References:
References:
- pidgin-knotify (pidgin-knotify)
- pidgin-knotify SQL vulnerability (Matthias Petschick )