7.5

CVE-2005-3539

Exploit
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hylafax ≫ Hylafax Version 4.1.1
Hylafax ≫ Hylafax Version 4.2
Hylafax ≫ Hylafax Version 4.2.1
Hylafax ≫ Hylafax Version 4.2.2
Hylafax ≫ Hylafax Version 4.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.65% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.hylafax.org/bugzilla/show_bug.cgi?id=719
http://secunia.com/advisories/18314
Patch
Vendor Advisory
http://secunia.com/advisories/18337
Patch
Vendor Advisory
http://secunia.com/advisories/18489
http://www.gentoo.org/security/en/glsa/glsa-200601-03.xml
Patch
Vendor Advisory
http://www.hylafax.org/content/HylaFAX_4.2.4_release
http://www.mandriva.com/security/advisories?name=MDKSA-2006:015
http://www.securityfocus.com/archive/1/420974/100/0/threaded
http://www.vupen.com/english/advisories/2006/0072
http://secunia.com/advisories/18366
http://www.debian.org/security/2005/dsa-933
http://www.securityfocus.com/bid/16151
Patch
Exploit