Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OnlineArts DailyDose dose.pl Remote Command Execution Vulnerability

It has been reported that DailyDose may be prone to a remote command execution vulnerability due to insufficient sanitization of $temp variable in dose.pl script. An attacker may submit arbitrary commands that will be executed in the context of the web server hosting the vulnerable script.

DailyDose v 1.1 has been reported to be prone to this issue however other versions may be affected as well.







 

Privacy Statement
Copyright 2009, SecurityFocus