OSVDB ID: 40521

Title: Alcatel OmniPCX Enterprise Communication Server Unified Maintenance Tool masterCGI user Variable Arbitrary Command Execution

Info

Disclosure

Sep 17, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote command execution vulnerability exists in Alcatel-Lucent OmniPCX Enterprise Communication Server. The Unified Maintenance Tool fails to filter shell metacharacters resulting in unauthenticated command execution.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified, Vendor Verified, Coordinated Disclosure

Solution

Upgrade to version 7.1 patch F5.401.19 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Alcatel

OmniPCX Enterprise Communication Server

7.1

References

Credit

  • RedTeam Pentesting - RedTeam Pentesting


Direct URL: http://osvdb.org/40521