Логотип exploitDog
bind:CVE-2012-3366
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-3366

Количество 4

Количество 4

ubuntu логотип

CVE-2012-3366

больше 13 лет назад

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server). This is very similar to a flaw discovered last year in a large number of other plugins; this instance was not fixed at that time because Trigger uses a different method to invoke external shell commands, and because Trigger previously hid all errors from trigger scripts, so tests did not find the issue. As a side effect of this change, Trigger will begin reporting errors from triggered scripts. This only affects the Trigger plugin; if you are not using Trigger, you are not affected by this flaw. As a workaround, you can disable Trigger until you are able to upgrade."

CVSS2: 9
EPSS: Низкий
nvd логотип

CVE-2012-3366

больше 13 лет назад

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).

CVSS2: 9
EPSS: Низкий
debian логотип

CVE-2012-3366

больше 13 лет назад

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers ...

CVSS2: 9
EPSS: Низкий
github логотип

GHSA-pg2p-q27f-4f79

больше 3 лет назад

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-3366

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server). This is very similar to a flaw discovered last year in a large number of other plugins; this instance was not fixed at that time because Trigger uses a different method to invoke external shell commands, and because Trigger previously hid all errors from trigger scripts, so tests did not find the issue. As a side effect of this change, Trigger will begin reporting errors from triggered scripts. This only affects the Trigger plugin; if you are not using Trigger, you are not affected by this flaw. As a workaround, you can disable Trigger until you are able to upgrade."

CVSS2: 9
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3366

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).

CVSS2: 9
2%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3366

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers ...

CVSS2: 9
2%
Низкий
больше 13 лет назад
github логотип
GHSA-pg2p-q27f-4f79

The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу