PT-2005-5364 · Tellme · Tellme

CVE-2005-4699

·

Publicado

2005-12-31

·

Atualizado

2024-02-13

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions TellMe versions 1.2 and earlier
Description The issue allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q Host parameter.
Recommendations For TellMe versions 1.2 and earlier, consider restricting access to the Whois program or limiting the use of the q Host parameter until a fix is available. As a temporary workaround, avoid using the "--" style options in the q Host parameter to minimize the risk of exploitation.

Exploit

Correção

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-4699

Produtos afetados

Tellme