PT-2005-2900 · E107 · Eping Plugin

Oliver Monneke

·

Published

2005-06-14

·

Updated

2024-02-14

·

CVE-2005-1949

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ePing plugin for e107 portal (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping host parameter in the eping validaddr function.
Recommendations For the ePing plugin, consider restricting access to the eping validaddr function until a patch is available. Avoid using the eping host parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2005-1949

Affected Products

Eping Plugin