PT-2002-1539 · Linux Directory Penguin · Linux Directory Penguin Traceroute.Pl Cgi Script
CVE-2002-0488
·
Publicado
2002-08-12
·
Atualizado
2024-02-14
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux Directory Penguin traceroute.pl CGI script version 1.0
Description
The issue allows remote attackers to execute arbitrary code via shell metacharacters in the
host parameter. This is a result of a flaw in the traceroute.pl CGI script.Recommendations
For Linux Directory Penguin traceroute.pl CGI script version 1.0, consider restricting access to the vulnerable CGI script until a patch is available. As a temporary workaround, avoid using the
host parameter in the affected CGI script to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Directory Penguin Traceroute.Pl Cgi Script