A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${IFS}-a leads to command injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-228911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.228911 Permissions Required Third Party Advisory
https://vuldb.com/?id.228911 Permissions Required Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-05-12T12:31:06.112Z

Updated: 2023-10-23T06:08:43.143Z

Reserved: 2023-05-12T12:17:09.253Z


Link: CVE-2023-2682

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-05-12T13:15:09.477

Modified: 2024-05-17T02:23:10.720


Link: CVE-2023-2682

JSON object: View

cve-icon Redhat Information

No data.

CWE