PT-2018-4115 · Ice Cold Apps · Ice Cold Apps Servers Ultimate

Larry W. Cashdollar

+1

·

Publicado

2018-10-05

·

Atualizado

2019-01-08

·

CVE-2013-7465

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ice Cold Apps Servers Ultimate version 6.0.2(12)
Description The issue allows remote attackers to execute arbitrary code by uploading PHP scripts due to a lack of authentication requirement for TELNET, SSH, or FTP.
Recommendations For version 6.0.2(12), consider implementing authentication for TELNET, SSH, and FTP to prevent unauthorized access and restrict the ability to upload PHP scripts until a proper fix is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-7465

Produtos afetados

Ice Cold Apps Servers Ultimate