PT-2020-16099 · Xinuos · Openserver

Ramikan

·

Published

2020-12-18

·

Updated

2021-07-21

·

CVE-2020-25494

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xinuos (formerly SCO) Openserver versions v5 and v6
Description The issue allows attackers to execute arbitrary commands via shell metacharacters in the outputform or toclevels parameter to "cgi-bin/printbook".
Recommendations For Xinuos (formerly SCO) Openserver versions v5 and v6, consider restricting access to the "cgi-bin/printbook" endpoint until a patch is available. As a temporary workaround, avoid using the outputform and toclevels parameters in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25494

Affected Products

Openserver