This application requires Javascript for optimal performance.

CVSTrac.FileDiff.Parameter.Command.Execution

Release Date

Dec 17, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a remote command-execution vulnerability in CVSTrac.

The vulnerability is caused by an error when the vulnerable software handles a malicious "FileDiff" property. It allows a remote attacker to execute arbitrary commands via sending a crafted web request.

Affected Products

CVSTrac 1.1.3
CVSTrac 1.1.2
CVSTrac 1.1.1

Recommended Actions

Upgrade the software to the latest versions.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2004-1456

Reference/s

http://www.securityfocus.com/bid/10878 (BugTraq)

Reference: VID-17871