This application requires Javascript for optimal performance.

Traq.Authenticate.Function.Remote.Code.Execution

Release Date

Jan 12, 2012

Severity

high

Impact

System Compromise: Remote attackers can remote execute arbitrary code.

Description

This indicates an attack attempt against a Remote Command Execution vulnerability in in Traq.

The vulnerability is caused by a broken authorization schema which doesn't stop the execution flow from an unauthorized user. It allows a remote attacker to execute arbitrary code via sending a crafted HTTP request.

Affected Products

Traq 2.0 to 2.3

Recommended Actions

Upgrade to the latest version, available from the website.
http://traqproject.org/

Coverage

IPS
VCM

Reference/s

http://www.exploit-db.com/exploits/18213/
http://www.securityfocus.com/bid/50961 (BugTraq)

Reference: VID-30631