Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows...
Vulnerability Description
Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) transcriptFile parameter to MRcgi/MRchat.pl or (2) LOADFILE parameter to MRcgi/MRABLoad2.pl. NOTE: some of these details are obtained from third party information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-7158
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/42816
- https://footprintssupport.numarasoftware.com/MRcgi/MRTicketPage.pl?USER=&MRP=0&PROJECTID=4&MR=89552&MAXMININC=&MAJOR_MODE=DETAILS
- http://secunia.com/advisories/28390
- http://www.securityfocus.com/bid/27373
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39810
- http://osvdb.org/42813
Affected Vendor
numarasoftware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.