83363 : bcfg2 Trigger Plugin UUID Field Parsing Remote Shell Command Execution Printer | http://osvdb.org/83363 | Email This | Edit Vulnerability
bcfg2 contains a flaw in the Trigger plugin that occurs when input is not properly sanitized during the parsing of the UUID field when it is received from another client. This may allow a remote attacker to execute arbitrary shell commands.
Upgrade to version 1.2.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
CVSSv2 Base Score = 9.0 Source: nvd.nist.gov | Generated: 2012-07-03 | Disagree?
Add Comment Hide Add Comment