Lucene search

K
cve[email protected]CVE-2003-1538
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2003-1538

2022-10-0316:15:42
CWE-20
web.nvd.nist.gov
25
cve-2003-1538
susehelp
suse linux
remote code execution
shell metacharacters
security vulnerability

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.7%

susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

Affected configurations

NVD
Node
susesuse_linux_openexchange_serverMatch4.0
OR
suseoffice_server
OR
susesuse_linuxMatch8enterprise_server
OR
susesuse_linuxMatch8.1

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.7%

Related for CVE-2003-1538