oboinus Remote Arbitrary Shell Command Injection Vulnerability
BID:49706
Info
oboinus Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 49706 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2011 12:00AM |
| Updated: | Mar 19 2015 08:40AM |
| Credit: | naplanetu |
| Vulnerable: |
oboinus obonius 2.1 |
| Not Vulnerable: |
oboinus obonius 2.2 |
Discussion
oboinus Remote Arbitrary Shell Command Injection Vulnerability
oboinus mail is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
oboinus mail is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with the privileges of the user running the application.
Exploit / POC
oboinus Remote Arbitrary Shell Command Injection Vulnerability
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
oboinus Remote Arbitrary Shell Command Injection Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
oboinus Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- Log message Fixed possible shell injection risk through os.system() (oboinus)
- oboinus Homepage (oboinus)