PT-2001-2017 · Viralator · Viralator
Published
2001-11-22
·
Updated
2017-12-19
·
CVE-2001-0849
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Viralator versions 0.9pre1 and earlier
Description
The issue concerns the viralator CGI script, which allows remote attackers to execute arbitrary code. This is achieved by insecurely passing a URL for a file being downloaded to a call to
wget.Recommendations
For versions 0.9pre1 and earlier, consider disabling the viralator CGI script until a secure version is available. Restrict access to the
wget call to minimize the risk of exploitation. Avoid using the viralator CGI script for downloading files from untrusted sources until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Viralator