PT-2003-1269 · Unknown · Molly Irc Bot

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2002-1536

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Molly IRC bot version 0.5
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in several variables across different scripts, including the $host variable in nslookup.pl, the $to, $from, or $message variables in pop.pl, the $words or $text variables in sms.pl, and the $server or $printer variables in hpled.pl.
Recommendations For Molly IRC bot version 0.5, consider restricting or sanitizing input for the $host variable in nslookup.pl, the $to, $from, and $message variables in pop.pl, the $words and $text variables in sms.pl, and the $server and $printer variables in hpled.pl to prevent command execution. As a temporary workaround, consider disabling the execution of shell commands from these scripts until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1536

Affected Products

Molly Irc Bot