PT-2015-2445 · Icewind1991 · Icewind1991 Smb

Publicado

2015-10-21

·

Atualizado

2015-10-22

·

CVE-2015-7698

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions icewind1991 SMB versions prior to 1.0.3
Description The issue exists due to the lack of neutralization of special elements used in operating system commands. This allows a remote attacker to execute arbitrary SMB commands using special metacharacters in user arguments. Specifically, the listShares function in Server.php and the connect or read functions in Share.php are vulnerable to shell metacharacters in the user argument.
Recommendations For versions prior to 1.0.3, update to version 1.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the listShares function in Server.php and the connect or read functions in Share.php to minimize the risk of exploitation. Avoid using metacharacters in the user argument in the affected API endpoints until the issue is resolved.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11810
CVE-2015-7698

Produtos afetados

Icewind1991 Smb