Vulnerabilities > CVE-2006-6678 - Remote Arbitrary Command Execution vulnerability in Netrik 1.15.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1251.NASL |
description | It has been discovered that netrik, a text mode WWW browser with vi like keybindings, doesn |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24248 |
published | 2007-01-26 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24248 |
title | Debian DSA-1251-1 : netrick - insufficient escaping |
References
- http://netrik.cvs.sourceforge.net/netrik/netrik/form-file.c?r1=1.3&r2=1.4
- http://secunia.com/advisories/23822
- http://sourceforge.net/project/shownotes.php?release_id=472131&group_id=23183
- http://www.debian.org/security/2007/dsa-1251
- http://www.securityfocus.com/bid/22158
- http://www.vupen.com/english/advisories/2006/5092