Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
BID:67383
Info
Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 67383 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2014 12:00AM |
| Updated: | Sep 23 2014 12:01AM |
| Credit: | Dolev Farhi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
Openfiler is prone to an arbitrary code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application.
Openfiler 2.99.1 is vulnerable; other versions may also be affected.
Openfiler is prone to an arbitrary code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application.
Openfiler 2.99.1 is vulnerable; other versions may also be affected.
Exploit / POC
Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor supplied patches If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor supplied patches If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Openfiler 'Hostname' Field Arbitrary Code Execution Vulnerability
References:
References:
- Openfiler Homepage (Openfiler)