The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/515971/100/0/threaded | mailing list |
http://secunia.com/advisories/43037 | third party advisory |
http://www.securityfocus.com/bid/45987 | vdb entry |
http://www.openvas.org/OVSA20110118.html | exploit patch vendor advisory |
http://www.vupen.com/english/advisories/2011/0208 | vdb entry vendor advisory |
http://osvdb.org/70639 | vdb entry |
http://www.exploit-db.com/exploits/16086 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65011 | vdb entry |