PT-2002-2692 · Sourcecraft · Sourcecraft Networking Utils

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1971

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sourcecraft Networking Utils version 1.0
Description The issue allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument. This is due to a problem in the ping utility in networking utils.php.
Recommendations For Sourcecraft Networking Utils version 1.0, consider validating and sanitizing the Domain name and IP address arguments to prevent shell metacharacter injection. As a temporary workaround, restrict access to the ping utility until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1971

Produtos afetados

Sourcecraft Networking Utils