Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.12637 |
Categoría: | Gain a shell remotely |
Título: | Open WebMail vacation.pl Arbitrary Command Execution |
Resumen: | The target is running at least one instance of Open WebMail in which; the vacation.pl component fails to sufficiently validate user input. |
Descripción: | Summary: The target is running at least one instance of Open WebMail in which the vacation.pl component fails to sufficiently validate user input. Vulnerability Insight: If safe_checks are disabled, the scanner attempts to create the file /tmp/ Vulnerability Impact: This failure enables remote attackers to execute arbitrary programs on a target using the privileges under which the web server operates. Solution: Upgrade to Open WebMail version 2.32 20040629 or later. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Referencia Cruzada: |
BugTraq ID: 10637 Common Vulnerability Exposure (CVE) ID: CVE-2004-2284 http://www.securityfocus.com/bid/10637 http://www.osvdb.org/7474 http://securitytracker.com/id?1010605 http://secunia.com/advisories/12017 XForce ISS Database: open-webmail-vacation-program-execution(16549) https://exchange.xforce.ibmcloud.com/vulnerabilities/16549 |
Copyright | Copyright (C) 2004 George A. Theall |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |