SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
BID:47139
Info
SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
| Bugtraq ID: | 47139 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2011 12:00AM |
| Updated: | Apr 04 2011 12:00AM |
| Credit: | Reported by SUSE |
| Vulnerable: |
S.u.S.E. SUSE Linux Enterprise Server 10 SP3 S.u.S.E. SUSE Linux Enterprise Server 10 SP2 S.u.S.E. SUSE Linux Enterprise Server 10 SP1 S.u.S.E. SUSE Linux Enterprise Server 10 |
| Not Vulnerable: | |
Discussion
SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
SUSE sap-es-tools is prone to a remote command-injection vulnerability.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application.
SUSE sap-es-tools is prone to a remote command-injection vulnerability.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application.
Exploit / POC
SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
SUSE sap-es-tools CGI Scripts Remote Command Injection Vulnerability
References:
References:
- SUSE Linux Homepage (Novell)