Webfroot Shoutbox Remote Command Execution Vulnerability
BID:7746
Info
Webfroot Shoutbox Remote Command Execution Vulnerability
| Bugtraq ID: | 7746 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2003 12:00AM |
| Updated: | May 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to pokleyzz <[email protected]>. |
| Vulnerable: |
Webfroot Shoutbox 2.32 |
| Not Vulnerable: | |
Discussion
Webfroot Shoutbox Remote Command Execution Vulnerability
Shoutbox is prone to an issue that may result in the execution of attacker-supplied code. The vulnerability exists due to insufficient sanitization of the 'conf' URI parameter.
An attacker can exploit this vulnerability to execute arbitrary commands on a vulnerable system using the PHP interpreter.
Shoutbox is prone to an issue that may result in the execution of attacker-supplied code. The vulnerability exists due to insufficient sanitization of the 'conf' URI parameter.
An attacker can exploit this vulnerability to execute arbitrary commands on a vulnerable system using the PHP interpreter.