PT-2002-1539 · Linux Directory Penguin · Linux Directory Penguin Traceroute.Pl Cgi Script

Published

2002-08-12

·

Updated

2024-02-14

·

CVE-2002-0488

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Directory Penguin traceroute.pl CGI script version 1.0
Description The issue allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. This is a result of a flaw in the traceroute.pl CGI script.
Recommendations For Linux Directory Penguin traceroute.pl CGI script version 1.0, consider restricting access to the vulnerable CGI script until a patch is available. As a temporary workaround, avoid using the host parameter in the affected CGI script to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2002-0488

Affected Products

Linux Directory Penguin Traceroute.Pl Cgi Script