10

CVE-2008-5810

WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.76% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bs2www.fujitsu-siemens.de/update/securitypatch.htm#english
Patch
http://secunia.com/advisories/33168
Patch
Vendor Advisory
http://securityreason.com/securityalert/4856
http://www.sec-consult.com/files/20081219-0_fujitsu-siemens_webta_cmdexec.txt
http://www.securityfocus.com/archive/1/499417/100/0/threaded
http://www.securityfocus.com/bid/32927
http://www.securitytracker.com/id?1021475
http://www.vupen.com/english/advisories/2008/3462
https://exchange.xforce.ibmcloud.com/vulnerabilities/47495