OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures.
References
Configurations
History
21 Nov 2024, 00:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/27525 - Vendor Advisory | |
References | () http://www.netragard.com/pdfs/research/NETRAGARD-20070313-OPENBASE.txt - Exploit | |
References | () http://www.securityfocus.com/bid/26347 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38291 - |
Information
Published : 2007-11-10 02:46
Updated : 2024-11-21 00:38
NVD link : CVE-2007-5926
Mitre link : CVE-2007-5926
CVE.ORG link : CVE-2007-5926
JSON object : View
Products Affected
openbase_international_ltd
- openbase
CWE
CWE-20
Improper Input Validation