PT-2005-3570 · Virtual Edge · Virtual Edge Netquery

Publicado

2005-08-23

·

Atualizado

2008-09-05

·

CVE-2005-2684

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Virtual Edge Netquery version 3.11
Description The issue allows remote attackers to execute arbitrary commands. This is achieved by using shell metacharacters in the host parameter to a dig query in the nquser.php file.
Recommendations For Virtual Edge Netquery version 3.11, consider restricting access to the nquser.php file or the dig query functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the host parameter in the dig query until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2684

Produtos afetados

Virtual Edge Netquery