PT-2002-2547 · Wasd · Wasd

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1825

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions WASD versions 7.1, 7.2.0 through 7.2.3, 8.0.0
Description The issue allows remote attackers to execute arbitrary commands or crash the server via format strings in the name variable.
Recommendations For WASD versions 7.1, 7.2.0 through 7.2.3, and 8.0.0, avoid using format strings in the name variable until a fix is available. As a temporary workaround, consider restricting access to the vulnerable script PerlRTE example1.pl to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1825

Produtos afetados

Wasd