NOALYSS 'backup.php' Remote Command Execution Vulnerability
BID:70205
Info
NOALYSS 'backup.php' Remote Command Execution Vulnerability
| Bugtraq ID: | 70205 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6389 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2014 12:00AM |
| Updated: | Sep 23 2014 12:00AM |
| Credit: | Jerzy Kramarz |
| Vulnerable: |
NOALYSS NOALYSS 6.7.1 5638 |
| Not Vulnerable: |
NOALYSS NOALYSS 6.7.2 |
Discussion
NOALYSS 'backup.php' Remote Command Execution Vulnerability
NOALYSS is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
NOALYSS 6.7.1 5638 is vulnerable; other versions may also be affected.
NOALYSS is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
NOALYSS 6.7.1 5638 is vulnerable; other versions may also be affected.
Exploit / POC
NOALYSS 'backup.php' Remote Command Execution Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
NOALYSS 'backup.php' Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.