First published: Tue Jun 11 2002(Updated: )
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun SunOS | =5.7 | |
Sun SunOS | =5.8 | |
Oracle Solaris SPARC | =7.0 | |
Oracle Solaris SPARC | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0436 has a high severity rating due to its ability to allow remote attackers to execute arbitrary commands.
To fix CVE-2002-0436, you should update your affected SunOS or Solaris systems to a version that does not include the vulnerable CGI script.
CVE-2002-0436 affects SunOS versions 5.7, 5.8, and Solaris versions 7.0 and 8.0 running on x86 and SPARC architectures.
CVE-2002-0436 is a command injection vulnerability that arises from inadequate input validation in a CGI script.
Yes, CVE-2002-0436 can lead to data breaches as it allows attackers to execute arbitrary commands with potentially sensitive data exposure.