Vulnerability Description
Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux Directory Penguin | Linux Directory Penguin Traceroute | 1.0 |
References
- http://www.iss.net/security_center/static/8600.phpPatchVendor Advisory
- http://www.linux-directory.com/scripts/traceroute.plURL Repurposed
- http://www.securityfocus.com/archive/1/263285Vendor Advisory
- http://www.securityfocus.com/bid/4332PatchVendor Advisory
- http://www.iss.net/security_center/static/8600.phpPatchVendor Advisory
- http://www.linux-directory.com/scripts/traceroute.plURL Repurposed
- http://www.securityfocus.com/archive/1/263285Vendor Advisory
- http://www.securityfocus.com/bid/4332PatchVendor Advisory
FAQ
What is CVE-2002-0488?
CVE-2002-0488 is a vulnerability with a CVSS score of 10.0 (HIGH). Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.
How severe is CVE-2002-0488?
CVE-2002-0488 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0488?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Directory Penguin Linux Directory Penguin Traceroute.