Netjuke远程命令执行漏洞

漏洞信息详情

Netjuke远程命令执行漏洞

漏洞简介

Artekopia Netjuke 1.0 b7之前版本存在漏洞。远程攻击者可能通过section参数可以执行在web服务器上的任意代码,该漏洞被传给eval调用。

漏洞公告

Netjuke has released 1.0b6.2 patch for versions 1.0 b3 through b6 which will address this issue. However, it is recommended to upgrade to 1.0b7 which also addresses this issue:
Netjuke Netjuke 1.0 b6

Netjuke Netjuke 1.0 b1

Netjuke Netjuke 1.0 b4

Netjuke Netjuke 1.0 b2

Netjuke Netjuke 1.0 b3

Netjuke Netjuke 1.0 b5

参考网址

来源: BID
名称: 3988
链接:http://www.securityfocus.com/bid/3988

来源: sourceforge.net
链接:http://sourceforge.net/tracker/index.php?func=detail&aid=507312&group_id=42076&atid=432052

来源: XF
名称: netjuke-section-command-execution(8101)
链接:http://xforce.iss.net/xforce/xfdb/8101

来源: sourceforge.net
链接:http://sourceforge.net/tracker/index.php?func=detail&aid=507312&group_id=42076&atid=432052

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享