Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
BID:7809
Info
Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
| Bugtraq ID: | 7809 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2003 12:00AM |
| Updated: | Jun 04 2003 12:00AM |
| Credit: | Discovery is credited to Joao Gouveia <[email protected]>. |
| Vulnerable: |
Computer Associates Unicenter TNG 2.4.2 Computer Associates Unicenter TNG 2.4 Computer Associates Unicenter TNG 2.1 Computer Associates Unicenter ServicePlus Service Desk 6.0 Computer Associates Unicenter ServicePlus Service Desk 5.5.1 Computer Associates Unicenter ServicePlus Service Desk 5.5 |
| Not Vulnerable: | |
Discussion
Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
Computer Associates Unicenter TNG is reported to be prone to a remote command execution vulnerability. This issue exists in the 'file_upload.pl' script. The vulnerability could be exploited to execute malicious commands in the context of the software.
Computer Associates Unicenter TNG is reported to be prone to a remote command execution vulnerability. This issue exists in the 'file_upload.pl' script. The vulnerability could be exploited to execute malicious commands in the context of the software.
Exploit / POC
Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
Solution:
The vendor has made solutions available for Unicenter ServicePlus Service Desk available via the eSupport web page. Customers should refer to this page for details on obtaining fixes.
Solution:
The vendor has made solutions available for Unicenter ServicePlus Service Desk available via the eSupport web page. Customers should refer to this page for details on obtaining fixes.
References
Computer Associates Unicenter TNG File_Upload.PL Command Execution Vulnerability
References:
References:
- eSupport Homepage (Computer Associates)
- Re: CA Unicenter Password Recovery Tool (Joao Gouveia
)