The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote attackers to execute arbitrary commands via shell metacharacters in the Servername subparameter of the ParameterList parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/35257 | vdb entry |
http://www.securityfocus.com/archive/1/472800/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2007/2441 | vdb entry |
http://osvdb.org/37835 | vdb entry |
http://www.redteam-pentesting.de/advisories/rt-sa-2007-002.php | patch vendor advisory exploit |
http://securityreason.com/securityalert/2858 | third party advisory |
http://www.securityfocus.com/bid/24762 | patch vdb entry exploit |
http://secunia.com/advisories/25944 | patch vendor advisory third party advisory |