7.5
CVSSv2

CVE-2005-3539

Published: 31/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and previous versions allow remote malicious users to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

Vulnerable Product Search on Vulmon Subscribe to Product

hylafax hylafax 4.1.1

hylafax hylafax 4.2

hylafax hylafax 4.2.1

hylafax hylafax 4.2.2

hylafax hylafax 4.2.3

Vendor Advisories

Debian Bug report logs - #347298 hylafax-server: Security concern in notify script CVE-2005-3539 Package: hylafax-server; Maintainer for hylafax-server is Giuseppe Sacco <eppesuig@debianorg>; Source for hylafax-server is src:hylafax (PTS, buildd, popcon) Reported by: Ernst Oudhof <ernst@mailfromnl> Date: Mon, 9 Ja ...

Exploits

source: wwwsecurityfocuscom/bid/16151/info HylaFAX is vulnerable to multiple arbitrary command-execution vulnerabilities This issue is due to a failure in the application to properly sanitize user-supplied input These vulnerabilities allow an attacker to execute arbitrary commands in the context of the affected application Successful ...