The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1002 | patch vendor advisory vdb entry |
http://www.securityfocus.com/templates/archive.pike?list=1&msg=38B3E60A.6A84FEC3%40cybcom.net | mailing list |
http://www.sambar.com/session/highlight?url=/syshelp/history.htm&words=security+&color=red | vendor advisory |