CVE-2012-0261: Code Injection
Published Dec 31, 2013
·Updated
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.
Affected Software
6 affected components
OP5 Monitor<=5.5.1
OP5 Monitor=5.3.5
OP5 Monitor=5.4.0
OP5 Monitor=5.4.2
OP5 Monitor=5.5.0
op5 system-portal<=1.6.1
Event History
Dec 31, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0261?
CVE-2012-0261 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-0261?
To fix CVE-2012-0261, upgrade op5 Monitor to version 5.5.2 or later and op5 System-portal to version 1.6.2 or later.
3
What impact does CVE-2012-0261 have on affected systems?
CVE-2012-0261 allows remote attackers to execute arbitrary commands, potentially compromising the entire system.
4
Which versions of op5 Monitor are affected by CVE-2012-0261?
Versions of op5 Monitor prior to 5.5.2, including 5.3.5, 5.4.0, 5.4.2, and 5.5.0, are affected by CVE-2012-0261.
5
Which versions of op5 System-portal are affected by CVE-2012-0261?
op5 System-portal versions up to and including 1.6.1 are affected by CVE-2012-0261.