Release DateJan 12, 2012 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can remote execute arbitrary code. |
DescriptionThis indicates an attack attempt against a Remote Command Execution vulnerability in in Traq.The vulnerability is caused by a broken authorization schema which doesn't stop the execution flow from an unauthorized user. It allows a remote attacker to execute arbitrary code via sending a crafted HTTP request. |
Affected ProductsTraq 2.0 to 2.3 |
Recommended ActionsUpgrade to the latest version, available from the website.http://traqproject.org/ |
Coverage IPS
VCM |
Reference/shttp://www.exploit-db.com/exploits/18213/http://www.securityfocus.com/bid/50961 (BugTraq) |