9.3
CVSSv2

CVE-2008-3285

Published: 24/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Filesys::SmbClientParser module 2.7 and previous versions for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

alain barbet filesys smbclientparser 2.2

alain barbet filesys smbclientparser 2.3

alain barbet filesys smbclientparser 2.4

alain barbet filesys smbclientparser 2.5

alain barbet filesys smbclientparser 2.6

alain barbet filesys smbclientparser 2.7

alain barbet filesys smbclientparser 2.1

Exploits

source: wwwsecurityfocuscom/bid/30290/info The SmbClientParser Perl module is prone to a remote command-execution vulnerability because it fails to sufficiently sanitize user-supplied data Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running applications that use ...