|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
The vulnerability occurs in the routine that reads and converts user input from hexidecimal. The routine assigns values to all variable names accordingly as specified in the HTTP POST request (guestbook posts are POSTed). An attacker can send a hand crafted POST request which will execute arbitrary commands on the server.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s): Replace the vulnerable code in the guestbook so that it checks the values of the important variables after user input. Sample code is available.
|
|
Products |
|
Guestbook
 |
0.x |
1.x |
2.x |
3.0 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|