Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Erik Smit

#17421de 53,634
15.4CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2009-4022
8.5
2009-05-05
Jbmc · Directadmin · CVE-2009-1525
Name of the Vulnerable Software and Affected Versions: DirectAdmin versions prior to 1.334 Description: The issue allows remote authenticated users to gain privileges via shell metacharacters in the `name` parameter during a restore action. This is related to the CMD DB in JBMC Software. Recommendations: For versions prior to 1.334, update to version 1.334 or later to resolve the issue. As a temporary workaround, consider restricting access to the restore action to minimize the risk of exploitation. Avoid using shell metacharacters in the `name` parameter until the issue is resolved.
PT-2009-4023
6.9
2009-05-05
Jbmc · Directadmin · CVE-2009-1526
Name of the Vulnerable Software and Affected Versions: JBMC Software DirectAdmin versions prior to 1.334 Description: The issue allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory. This is related to a request for this temporary file in the PATH INFO to the CMD DB script during a backup action. Recommendations: For versions prior to 1.334, update to version 1.334 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary directory and the CMD DB script to minimize the risk of exploitation.