PT-2002-1488 · Sun · Sun Sunsolve Cd Pack
Publicado
2002-06-11
·
Atualizado
2018-10-30
·
CVE-2002-0436
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Sunsolve CD pack version (affected versions not specified)
Description
The issue concerns the sscd suncourier.pl CGI script, which allows remote attackers to execute arbitrary commands. This is achieved by injecting shell metacharacters into the
email address parameter.Recommendations
For the affected version, consider restricting access to the sscd suncourier.pl CGI script until a fix is available. As a temporary workaround, avoid using the
email address parameter in the vulnerable script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sun Sunsolve Cd Pack