PT-2002-2692 · Sourcecraft · Sourcecraft Networking Utils
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1971
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sourcecraft Networking Utils version 1.0
Description
The issue allows remote attackers to read arbitrary files via shell metacharacters in the
Domain name or IP address argument. This is due to a problem in the ping utility in networking utils.php.Recommendations
For Sourcecraft Networking Utils version 1.0, consider validating and sanitizing the
Domain name and IP address arguments to prevent shell metacharacter injection. As a temporary workaround, restrict access to the ping utility until a proper fix is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecraft Networking Utils