Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kismet ESSID远程命令执行漏洞
Vulnerability Description
Kismet是一款由Kismet开发组维护的免费开放源代码802.11b 网络嗅探程序。 Kismet对用户提交的数据缺少正确充分的过滤,可导致远程攻击者以Kismet进程的权限在系统上执行任意命令。 问题存在kismet_curses.cc: SayText(festival, text);代码中,直接传递text数据并由下列调用: kismet_server.cc: snprintf(snd_call, 1024, "echo '(SayText \"%s\")' | %s &", text.c_st
CVSS Information
N/A
Vulnerability Type
N/A