PT-2005-5364 · Tellme · Tellme

Published

2005-12-31

·

Updated

2024-02-13

·

CVE-2005-4699

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions TellMe versions 1.2 and earlier
Description The issue allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q Host parameter.
Recommendations For TellMe versions 1.2 and earlier, consider restricting access to the Whois program or limiting the use of the q Host parameter until a fix is available. As a temporary workaround, avoid using the "--" style options in the q Host parameter to minimize the risk of exploitation.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2005-4699

Affected Products

Tellme