PT-2003-1269 · Unknown · Molly Irc Bot
Published
2003-03-18
·
Updated
2008-09-05
·
CVE-2002-1536
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Molly IRC bot version 0.5
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in several variables across different scripts, including the $host variable in nslookup.pl, the $to, $from, or $message variables in pop.pl, the $words or $text variables in sms.pl, and the $server or $printer variables in hpled.pl.
Recommendations
For Molly IRC bot version 0.5, consider restricting or sanitizing input for the $host variable in nslookup.pl, the $to, $from, and $message variables in pop.pl, the $words and $text variables in sms.pl, and the $server and $printer variables in hpled.pl to prevent command execution. As a temporary workaround, consider disabling the execution of shell commands from these scripts until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Molly Irc Bot