PT-2002-1539 · Linux Directory Penguin · Linux Directory Penguin Traceroute.Pl Cgi Script
Published
2002-08-12
·
Updated
2024-02-14
·
CVE-2002-0488
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux Directory Penguin traceroute.pl CGI script version 1.0
Description
The issue allows remote attackers to execute arbitrary code via shell metacharacters in the
host parameter. This is a result of a flaw in the traceroute.pl CGI script.Recommendations
For Linux Directory Penguin traceroute.pl CGI script version 1.0, consider restricting access to the vulnerable CGI script until a patch is available. As a temporary workaround, avoid using the
host parameter in the affected CGI script to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Directory Penguin Traceroute.Pl Cgi Script