PT-2018-9229 · Security Onion Solutions · Squert
Jeffrey Medsger
·
Publicado
2018-02-09
·
Atualizado
2018-03-01
·
CVE-2018-1000042
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Security Onion Solutions Squert versions 1.3.0 through 1.6.7
Description:
The issue is related to an OS Command Injection vulnerability in the .inc/callback.php file. This can result in the execution of OS commands. The attack is exploitable via a web request to .inc/callback.php with a payload in the
data or obj parameters, used in the autocat() function.Recommendations:
For versions 1.3.0 through 1.6.7, update to version 1.7.0 to resolve the issue.
As a temporary workaround, consider restricting access to the .inc/callback.php file and avoiding the use of the
data and obj parameters in the autocat() function until the update is applied.Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Squert