Mutiny CVE-2012-3001 Command Injection Vulnerability
BID:56165
Info
Mutiny CVE-2012-3001 Command Injection Vulnerability
| Bugtraq ID: | 56165 |
| Class: | Unknown |
| CVE: |
CVE-2012-3001 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2012 12:00AM |
| Updated: | Mar 25 2013 07:16AM |
| Credit: | Christopher Campbell |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Mutiny CVE-2012-3001 Command Injection Vulnerability
Mutiny is prone to a command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands with root privileges.
Mutiny versions prior to 4.5-1.12 are vulnerable.
Mutiny is prone to a command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands with root privileges.
Mutiny versions prior to 4.5-1.12 are vulnerable.
Exploit / POC
Mutiny CVE-2012-3001 Command Injection Vulnerability
The following metasploit exploit code is available:
The following metasploit exploit code is available:
Solution / Fix
Mutiny CVE-2012-3001 Command Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Mutiny CVE-2012-3001 Command Injection Vulnerability
References:
References: