PT-1999-1604 · Website Pro+1 · Website Pro+1

Publicado

1999-02-16

·

Atualizado

2008-09-10

·

CVE-1999-1180

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions O'Reilly WebSite version 1.1e Website Pro version 2.0
Description The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in an argument to either the args.cmd or args.bat functions.
Recommendations For O'Reilly WebSite version 1.1e, consider disabling the args.cmd and args.bat functions until a patch is available. For Website Pro version 2.0, restrict access to the args.cmd and args.bat functions to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1180

Produtos afetados

O'Reilly Website
Website Pro