6
CVSSv2

CVE-2013-6719

Published: 06/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x up to and including 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tealeaf cx 7.1

ibm tealeaf cx 8.5

ibm tealeaf cx 8.6

ibm tealeaf cx 8.3

ibm tealeaf cx 8.4

ibm tealeaf cx 7.2

ibm tealeaf cx 8.0

ibm tealeaf cx 8.7

ibm tealeaf cx 8.8

ibm tealeaf cx 8.1

ibm tealeaf cx 8.2

Exploits

# IBM Tealeaf CX (v8 release 8) Remote OS Command Injection # Date: 11/08/2013 # Exploit author: drone # More information: www-01ibmcom/support/docviewwss?uid=swg21667630 # Vendor homepage: www-01ibmcom/software/info/tealeaf/ # Version: Version 8 Release 8 (likely all versions prior) # Tested on: Redhat Linux 62 # CVE: CVE-2013 ...