6.8

CVE-2006-6597

Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option in a telnet:// URI, which is configured to use hawin32.exe.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HilgraeveHyperaccess Version8.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.48% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

http://secunia.com/advisories/23366
Vendor Advisory
Broken Link
http://securityreason.com/securityalert/2045
Third Party Advisory
http://www.securityfocus.com/archive/1/454388/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/21594
Third Party Advisory
Broken Link
VDB Entry
http://www.vupen.com/english/advisories/2006/5013
Broken Link