7.5

CVE-2007-4925

The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EwirePayment Client Version1.60
EwirePayment Client Version1.70
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.17% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://osvdb.org/40523
http://secunia.com/advisories/26780
Vendor Advisory
http://www.fortconsult.net/images/pdf/advisory_feb2007.pdf
http://www.securityfocus.com/bid/25683
http://www.vupen.com/english/advisories/2007/3183