9.3
CVSSv2

CVE-2008-1136

Published: 04/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Utils::runScripts function in src/utils.cpp in vdccm 0.92 up to and including 0.10.0 in SynCE (SynCE-dccm) allows remote malicious users to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679.

Vulnerable Product Search on Vulmon Subscribe to Product

synce synce 0.10.0

synce synce 0.92

Exploits

source: wwwsecurityfocuscom/bid/27178/info SynCE is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data Attackers can exploit this issue to execute arbitrary commands in the context of the application, facilitating the remote compromise of affected computers SynCE 092 is ...