PT-2000-1573 · Quadrant · Big Brother
Published
2000-06-11
·
Updated
2017-10-10
·
CVE-2000-0639
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Big Brother versions 1.4h2 and earlier
Description
The default configuration does not include proper access restrictions, allowing remote attackers to execute arbitrary commands by uploading a file that will be executed as a CGI script by the web server.
Recommendations
For Big Brother versions 1.4h2 and earlier, consider configuring proper access restrictions to prevent remote attackers from uploading executable files. As a temporary workaround, restrict access to the bbd upload functionality until a proper configuration can be implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Big Brother