PT-2005-3570 · Virtual Edge · Virtual Edge Netquery
Published
2005-08-23
·
Updated
2008-09-05
·
CVE-2005-2684
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Virtual Edge Netquery version 3.11
Description
The issue allows remote attackers to execute arbitrary commands. This is achieved by using shell metacharacters in the
host parameter to a dig query in the nquser.php file.Recommendations
For Virtual Edge Netquery version 3.11, consider restricting access to the nquser.php file or the dig query functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the
host parameter in the dig query until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Virtual Edge Netquery