Vulnerabilities > CVE-2002-0436 - Unspecified vulnerability in SUN Solaris and Sunos
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
Exploit-Db
description | Solaris 7.0/8 Sunsolve CD SSCD_SunCourier.pl CGI Script Arbitrary Command Execution Vulnerability. CVE-2002-0436. Remote exploit for cgi platform |
id | EDB-ID:21340 |
last seen | 2016-02-02 |
modified | 2002-03-11 |
published | 2002-03-11 |
reporter | Fyodor |
source | https://www.exploit-db.com/download/21340/ |
title | Solaris 7.0/8 Sunsolve CD SSCD_SunCourier.pl CGI Script Arbitrary Command Execution Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | SSCD_INPUT.NASL |
description | The Sunsolve CD is part of the Solaris Media pack. It is included as a documentation resource, and is available for the Solaris Operating Environment. Sunsolve CD CGI scripts does not validate user input. Crackers may use them to execute some commands on your system. ** Note: Nessus did not try to perform the attack. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11066 |
published | 2002-08-06 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11066 |
title | Sun Sunsolve CD Pack sscd_suncourier.pl email Parameter Arbitrary Command Execution |
code |
|