|
Family: CGI abuses --> Category: infos
Ingo Foldername Command Execution Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks version number of Ingo
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is affected by a
command execution vulnerability.
Description :
According to its version number, the instance of Ingo installed on the
remote host fails to properly sanitize mailbox destinations in filter
rules. By using a folder name beginning with '|' as a mailbox
destination, an authenticated remote attacker may be able to exploit
this issue to execute arbitrary code on the remote host, subject to
the permissions of the web server user id.
See also :
http://bugs.horde.org/ticket/?id=4513
http://lists.horde.org/archives/announce/2006/000296.html
Solution :
Upgrade to Ingo version H3 (1.1.2) or later.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|