10
CVSSv2

CVE-2008-6555

Published: 30/03/2009 Updated: 11/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote malicious users to execute arbitrary commands via shell metacharacters in the dig command.

Vulnerable Product Search on Vulmon Subscribe to Product

puppetmaster webutil 2.3

puppetmaster webutil 2.7

Exploits

source: wwwsecurityfocuscom/bid/28393/info Webutil is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary commands These issues occur because the application fails to adequately sanitize user-supplied input Successful attacks can compromise the affected application and possibly the underlying computer T ...