PT-2005-3450 · E107 · E107 Eping Plugin

CVE-2005-2559

·

Publicado

2005-08-16

·

Atualizado

2024-02-14

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions e107 ePing plugin versions 1.02 and earlier
Description The issue allows remote attackers to execute arbitrary code or overwrite files. This can be achieved through shell metacharacters in the eping count parameter or restricted shell metacharacters such as ">" and "&" in the eping host parameter. The validation function does not properly handle these parameters.
Recommendations For e107 ePing plugin versions 1.02 and earlier, consider disabling the doping.php file until a patch is available. Restrict access to the eping count and eping host parameters to minimize the risk of exploitation. Avoid using restricted shell metacharacters in the eping host parameter.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2559

Produtos afetados

E107 Eping Plugin