HIGH · 10.0

CVE-2005-2259

The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Softw...

Vulnerability Description

The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Usanet CreationsDomain Name AuctionAll versions
Usanet CreationsMakebid Auction DeluxeAll versions
Usanet CreationsMakebid Auction StandardAll versions
Usanet CreationsMakebid Reverse AuctionAll versions
Usanet CreationsStandard Classified AdsAll versions
Usanet CreationsUsanet Shopping MallAll versions

References

FAQ

What is CVE-2005-2259?

CVE-2005-2259 is a vulnerability with a CVSS score of 10.0 (HIGH). The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Softw...

How severe is CVE-2005-2259?

CVE-2005-2259 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2259?

Check the references section above for vendor advisories and patch information. Affected products include: Usanet Creations Domain Name Auction, Usanet Creations Makebid Auction Deluxe, Usanet Creations Makebid Auction Standard, Usanet Creations Makebid Reverse Auction, Usanet Creations Standard Classified Ads.