T
he getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.
References
| Link | Resource |
|---|---|
| http://secunia.com/advisories/15582 | Patch Vendor Advisory |
| http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-06/0057.html | Vendor Advisory |
| http://secunia.com/advisories/15582 | Patch Vendor Advisory |
| http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-06/0057.html | Vendor Advisory |
Configurations
History
20 Nov 2024, 23:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://secunia.com/advisories/15582 - Patch, Vendor Advisory | |
| References | () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-06/0057.html - Vendor Advisory |
Information
Published : 2005-06-08 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-1960
Mitre link : CVE-2005-1960
CVE.ORG link : CVE-2005-1960
JSON object : View
Products Affected
CWE