Vulnerability Description
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avengers News System | Avengers News System | 2.01 |
References
- http://marc.info/?l=bugtraq&m=101430868616112&w=2
- http://www.securityfocus.com/bid/4149
- http://marc.info/?l=bugtraq&m=101430868616112&w=2
- http://www.securityfocus.com/bid/4149
FAQ
What is CVE-2002-0306?
CVE-2002-0306 is a vulnerability with a CVSS score of 7.5 (HIGH). ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
How severe is CVE-2002-0306?
CVE-2002-0306 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0306?
Check the references section above for vendor advisories and patch information. Affected products include: Avengers News System Avengers News System.