6.5
CVSSv2

CVE-2011-3195

Published: 21/03/2014 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

shared/inc/sql/lists.php in Domain Technologie Control (DTC) prior to 0.34.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in mailing list tunable options.

Vulnerable Product Search on Vulmon Subscribe to Product

gplhost domain technologie control 0.29.8

gplhost domain technologie control 0.28.9

gplhost domain technologie control 0.32.1

gplhost domain technologie control 0.25.3

gplhost domain technologie control 0.30.6

gplhost domain technologie control 0.26.9

gplhost domain technologie control 0.29.1

gplhost domain technologie control 0.27.3

gplhost domain technologie control 0.28.4

gplhost domain technologie control

gplhost domain technologie control 0.32.3

gplhost domain technologie control 0.28.10

gplhost domain technologie control 0.25.1

gplhost domain technologie control 0.30.18

gplhost domain technologie control 0.26.8

gplhost domain technologie control 0.28.6

gplhost domain technologie control 0.28.2

gplhost domain technologie control 0.32.2

gplhost domain technologie control 0.29.14

gplhost domain technologie control 0.29.17

gplhost domain technologie control 0.26.7

gplhost domain technologie control 0.29.16

gplhost domain technologie control 0.30.10

gplhost domain technologie control 0.32.6

gplhost domain technologie control 0.29.6

gplhost domain technologie control 0.28.3

gplhost domain technologie control 0.24.6

gplhost domain technologie control 0.32.5

gplhost domain technologie control 0.29.15

gplhost domain technologie control 0.29.10

gplhost domain technologie control 0.30.20

gplhost domain technologie control 0.30.8

gplhost domain technologie control 0.32.7

gplhost domain technologie control 0.32.4

gplhost domain technologie control 0.25.2

Vendor Advisories

Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple vulnerabilities in DTC, a web control panel for admin and accounting hosting services: CVE-2011-3195 A possible shell insertion has been found in the mailing list handling CVE-2011-3196 Unix rights for the apache2conf were set incorrectly (world readable) CVE-2 ...