CVE-2009-1525 Information

Description

CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0228.html http://osvdb.org/54015 http://secunia.com/advisories/34861 http://www.directadmin.com/features.php?id=968 https://exchange.xforce.ibmcloud.com/vulnerabilities/50167

Share on: