|
Dragon Fire IDS web interface may allow a remote attacker to execute arbitrary commands on the IDS host. The issue is due to the dfire.cgi script not properly sanitizing input to the "IP One" option. If an attacker provides a pipe (|) and arbitrary commands, it will be run with privilegs of the web script.
|