PT-2000-1572 · Unknown · Big Brother
Publicado
2000-07-11
·
Atualizado
2017-10-10
·
CVE-2000-0638
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Big Brother versions 1.4h1 and earlier
Description
The issue allows remote attackers to read arbitrary files via a .. (dot dot) attack on the
HOSTSVC parameter in the bb-hostsvc.sh script.Recommendations
For Big Brother versions 1.4h1 and earlier, consider restricting access to the bb-hostsvc.sh script to minimize the risk of exploitation. As a temporary workaround, avoid using the
HOSTSVC parameter in the affected script until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Big Brother