T
he (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacters in an argument, as demonstrated by an && (ampersand ampersand) sequence.
References
| Link | Resource |
|---|---|
| http://www.sec-1.com/blog/?p=211 | Exploit |
| http://www.sec-1.com/blog/?p=211 | Exploit |
Configurations
History
21 Nov 2024, 01:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.sec-1.com/blog/?p=211 - Exploit |
Information
Published : 2012-10-08 10:47
Updated : 2025-04-11 00:51
NVD link : CVE-2011-4639
Mitre link : CVE-2011-4639
CVE.ORG link : CVE-2011-4639
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')