First published: Thu Nov 22 2001(Updated: )
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yngve Svendsen Gnatsweb | =3.95-gnats_4 | |
Yngve Svendsen Gnatsweb | =2.7_beta | |
Yngve Svendsen Gnatsweb | =2.8.0 | |
Yngve Svendsen Gnatsweb | =2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0808 has a high severity rating due to its potential for remote code execution.
Fix CVE-2001-0808 by upgrading to a patched version of GnatsWeb that addresses this vulnerability.
CVE-2001-0808 affects GnatsWeb versions 2.7, 2.8.0, 2.8.1, and 3.95-gnats_4.
CVE-2001-0808 is classified as a command injection vulnerability.
Yes, CVE-2001-0808 can be exploited remotely by attackers to execute arbitrary commands.