PT-2005-3570 · Virtual Edge · Virtual Edge Netquery

Published

2005-08-23

·

Updated

2008-09-05

·

CVE-2005-2684

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Virtual Edge Netquery version 3.11
Description The issue allows remote attackers to execute arbitrary commands. This is achieved by using shell metacharacters in the host parameter to a dig query in the nquser.php file.
Recommendations For Virtual Edge Netquery version 3.11, consider restricting access to the nquser.php file or the dig query functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the host parameter in the dig query until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2684

Affected Products

Virtual Edge Netquery