PT-2000-1573 · Quadrant · Big Brother
Publicado
2000-06-11
·
Atualizado
2017-10-10
·
CVE-2000-0639
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Big Brother versions 1.4h2 and earlier
Description
The default configuration does not include proper access restrictions, allowing remote attackers to execute arbitrary commands by uploading a file that will be executed as a CGI script by the web server.
Recommendations
For Big Brother versions 1.4h2 and earlier, consider configuring proper access restrictions to prevent remote attackers from uploading executable files. As a temporary workaround, restrict access to the bbd upload functionality until a proper configuration can be implemented.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Big Brother