PT-2002-1539 · Linux Directory Penguin · Linux Directory Penguin Traceroute.Pl Cgi Script

CVE-2002-0488

·

Publicado

2002-08-12

·

Atualizado

2024-02-14

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Directory Penguin traceroute.pl CGI script version 1.0
Description The issue allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. This is a result of a flaw in the traceroute.pl CGI script.
Recommendations For Linux Directory Penguin traceroute.pl CGI script version 1.0, consider restricting access to the vulnerable CGI script until a patch is available. As a temporary workaround, avoid using the host parameter in the affected CGI script to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0488

Produtos afetados

Linux Directory Penguin Traceroute.Pl Cgi Script