PT-1999-1604 · Website Pro+1 · Website Pro+1
Publicado
1999-02-16
·
Atualizado
2008-09-10
·
CVE-1999-1180
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
O'Reilly WebSite version 1.1e
Website Pro version 2.0
Description
The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in an argument to either the
args.cmd or args.bat functions.Recommendations
For O'Reilly WebSite version 1.1e, consider disabling the
args.cmd and args.bat functions until a patch is available.
For Website Pro version 2.0, restrict access to the args.cmd and args.bat functions to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
O'Reilly Website
Website Pro