The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111868460811287&w=2 | mailing list |
http://www.securityfocus.com/bid/13934 | vdb entry vendor advisory |