The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111835539312985&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=111868460811287&w=2 | mailing list |
http://e107plugins.co.uk/news.php | url repurposed |
http://secunia.com/advisories/15678 | third party advisory |