Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cobalt RaQ4 Administrative Interface Command Execution Vulnerability

The RaQ4 is a server appliance distributed and maintained by Sun Microsystems.

A vulnerability has been reported in the web administration interface of the RaQ4. It is possible for a remote attacker to execute commands. By passing malicious email parameter to the vulnerable CGI script, commands are carried out in the security context of the administration server.

This vulnerability only affects RaQ4 servers with the RaQ4 Security Hardening Package (SHP) installed. The SHP is not installed by default.







 

Privacy Statement
Copyright 2009, SecurityFocus