CVE-2008-1331: Input Validation
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1331?
CVE-2008-1331 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2008-1331?
To address CVE-2008-1331, upgrade OmniPCX Office to version 210/091.001 or later for OXO210, and to version 610/014.001 or later for OXO600.
What systems are affected by CVE-2008-1331?
CVE-2008-1331 affects OmniPCX Office products, specifically versions prior to 210/091.001 for OXO210 and prior to 610/014.001 for OXO600.
What type of attack does CVE-2008-1331 facilitate?
CVE-2008-1331 allows remote attackers to execute arbitrary commands on affected systems through crafted input parameters.
Is there a workaround for CVE-2008-1331?
There are no recommended workarounds for CVE-2008-1331; patching the software is the only effective mitigation.