Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lionel Elie Mamane

#17982de 53,635
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2006-3170
7.5
2006-09-19
Gnu · Mailman · CVE-2006-2191
**Name of the Vulnerable Software and Affected Versions** Mailman versions prior to 2.1.9 **Description** A format string issue allows attackers to execute arbitrary code. The vendor has disputed this issue, stating it is unexploitable. **Recommendations** For versions prior to 2.1.9, update to version 2.1.9 or later to resolve the issue.
PT-2006-4022
7.5
2006-09-06
Hylafax · Capi4Hylafax · CVE-2006-3126
**Name of the Vulnerable Software and Affected Versions** capi4hylafax version 01.02.03 **Description** The issue allows remote attackers to execute arbitrary commands via null and shell metacharacters in the TSI string. This can be demonstrated by a fax from an anonymous number, which can include malicious input to exploit the weakness. **Recommendations** For capi4hylafax version 01.02.03, consider restricting or validating input for the TSI string to prevent the inclusion of null and shell metacharacters, which can be used to execute arbitrary commands. As a temporary workaround, restrict access to the c2faxrecv function until a patch is available.