|
|||
Rule General Information |
---|
Release Date: | 2014-05-29 | |
Rule Name: | Apache Win32 Batch File Remote Command Execution Vulnerability -2 (CVE-2002-0061) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Other Unix, Linux | |
Reference: | SecurityFocusBID:4335 |
|
Solutions |
---|
Upgrade to version 1.3.24 or 2.0.34 to solve the problem. |