Title: Alcatel OmniPCX Enterprise Communication Server Unified Maintenance Tool masterCGI user Variable Arbitrary Command Execution
Info
Disclosure
Sep 17, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
A remote command execution vulnerability exists in Alcatel-Lucent OmniPCX Enterprise Communication Server. The Unified Maintenance Tool fails to filter shell metacharacters resulting in unauthenticated command execution.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Vendor Verified,
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 7.1 patch F5.401.19 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.