PT-2005-3570 · Virtual Edge · Virtual Edge Netquery
Publicado
2005-08-23
·
Atualizado
2008-09-05
·
CVE-2005-2684
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Virtual Edge Netquery version 3.11
Description
The issue allows remote attackers to execute arbitrary commands. This is achieved by using shell metacharacters in the
host parameter to a dig query in the nquser.php file.Recommendations
For Virtual Edge Netquery version 3.11, consider restricting access to the nquser.php file or the dig query functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the
host parameter in the dig query until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Virtual Edge Netquery