PT-2001-2272 · Suse · Suse Linux
Published
2001-08-02
·
Updated
2017-10-10
·
CVE-2001-1130
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SuSE Linux versions 6.0 through 7.2
Description
The issue allows remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters. This is achieved by causing the file to be searched using a .. in the HTTP referer to point to the directory that contains the keylist.txt file, utilizing the
HTTP REFERER variable.Recommendations
For SuSE Linux versions 6.0 through 7.2, consider restricting access to the Sdbsearch.cgi script until a fix is available, and avoid using the
HTTP REFERER variable in a way that could allow directory traversal. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Linux