PT-2018-4115 · Ice Cold Apps · Ice Cold Apps Servers Ultimate

Larry W. Cashdollar

+1

·

Published

2018-10-05

·

Updated

2019-01-08

·

CVE-2013-7465

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ice Cold Apps Servers Ultimate version 6.0.2(12)
Description The issue allows remote attackers to execute arbitrary code by uploading PHP scripts due to a lack of authentication requirement for TELNET, SSH, or FTP.
Recommendations For version 6.0.2(12), consider implementing authentication for TELNET, SSH, and FTP to prevent unauthorized access and restrict the ability to upload PHP scripts until a proper fix is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7465

Affected Products

Ice Cold Apps Servers Ultimate