PT-2018-9229 · Security Onion Solutions · Squert

Jeffrey Medsger

·

Publicado

2018-02-09

·

Atualizado

2018-03-01

·

CVE-2018-1000042

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Security Onion Solutions Squert versions 1.3.0 through 1.6.7
Description: The issue is related to an OS Command Injection vulnerability in the .inc/callback.php file. This can result in the execution of OS commands. The attack is exploitable via a web request to .inc/callback.php with a payload in the data or obj parameters, used in the autocat() function.
Recommendations: For versions 1.3.0 through 1.6.7, update to version 1.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the .inc/callback.php file and avoiding the use of the data and obj parameters in the autocat() function until the update is applied.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000042

Produtos afetados

Squert