|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
News Desk contains a flaw that may allow a malicious user to read arbitrary file. The issue is triggered when an attacker submits a crafted request to the newsdesk.cgi script containing shell metacharacter sequences, which will allow the attacker to access arbitrary files on the system with the privileges of the HTTPD process, resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Newsdesk
 |
1.2 |
|
|
|
|
|
|
Credit |
- zenomorph - admin
cgisecurity.com - CGI Security
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|