Vulnerabilities > CVE-2006-0044 - Unspecified vulnerability in Albatross
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN albatross
nessus
Summary
Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the "handling of submitted form fields".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-942.NASL |
description | A design error has been discovered in the Albatross web application toolkit that causes user-supplied data to be used as part of template execution and hence arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22808 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22808 |
title | Debian DSA-942-1 : albatross - design error |
code |
|
References
- http://secunia.com/advisories/18457
- http://secunia.com/advisories/18457
- http://secunia.com/advisories/18496
- http://secunia.com/advisories/18496
- http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz
- http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz
- http://www.debian.org/security/2006/dsa-942
- http://www.debian.org/security/2006/dsa-942
- http://www.object-craft.com.au/projects/albatross/news.html
- http://www.object-craft.com.au/projects/albatross/news.html
- http://www.osvdb.org/22451
- http://www.osvdb.org/22451
- http://www.securityfocus.com/bid/16252
- http://www.securityfocus.com/bid/16252
- http://www.vupen.com/english/advisories/2006/0196
- http://www.vupen.com/english/advisories/2006/0196
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24130