PT-1998-1218 · Ray Chan · Ray Chan Www Authorization Gateway
Published
1998-07-08
·
Updated
2016-10-18
·
CVE-1999-1436
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ray Chan WWW Authorization Gateway version 0.1
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the
user parameter. This can be exploited by injecting malicious input into the vulnerable parameter.Recommendations
For Ray Chan WWW Authorization Gateway version 0.1, consider restricting access to the CGI program until a fix is available, and avoid using the
user parameter with untrusted input.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ray Chan Www Authorization Gateway