K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
BID:66297
Info
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
| Bugtraq ID: | 66297 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2527 CVE-2014-2528 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2014 12:00AM |
| Updated: | Apr 13 2015 08:21PM |
| Credit: | Adrian Panasiuk |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
K4DirStat is prone to a remote command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Versions prior to K4DirStat 2.7.5 are vulnerable.
K4DirStat is prone to a remote command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary OS commands in the context of the affected application.
Versions prior to K4DirStat 2.7.5 are vulnerable.
Exploit / POC
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
K4DirStat CVE-2014-2527 Remote Command Injection Vulnerability
References:
References: