REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
BID:60610
Info
REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 60610 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6567 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2012 12:00AM |
| Updated: | Jul 27 2012 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Vanderbilt University REDCap 4.13.18 |
| Not Vulnerable: |
Vanderbilt University REDCap 4.14.0 |
Discussion
REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
REDCap is prone to a remote arbitrary command-execution vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands in the context of the application.
REDCap is prone to a remote arbitrary command-execution vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary commands in the context of the application.
Exploit / POC
REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
REDCap CVE-2012-6567 Remote Arbitrary Command Execution Vulnerability
References:
References:
- REDCap Home Page (Vanderbilt University)
- REDCap Release Notes Version 4.13.18 �?? 5.0.6 (Vanderbilt University)