PT-2007-5277 · Cstr · Cstr Festival
Publicado
2007-07-30
·
Atualizado
2018-10-15
·
CVE-2007-4074
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
CSTR Festival version 1.95 beta (aka 2.0 beta)
Description:
The default configuration of CSTR Festival allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, due to it running with elevated privileges without requiring authentication. This issue can be local in some environments but remote in others.
Recommendations:
For version 1.95 beta (aka 2.0 beta), consider disabling the daemon on port 1314 until a proper configuration or patch is available to prevent unauthorized access and command execution. Restrict access to the daemon to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cstr Festival