Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cobalt RaQ4管理接口远程命令执行漏洞
Vulnerability Description
Cobalt RaQ是一个基于Internet的服务应用程序,由Sun微系统公司发布和维护。 Cobalt RaQ WEB管理接口在处理用户提供的EMAIL参数时缺少正确过滤,远程攻击者可以利用这个漏洞以WEB进程权限在系统上执行任意命令。 攻击者可以向Cobalt RaQ WEB管理接口中的CGI脚本的包含恶意EMAIL参数的请求,由于CGI脚本处理不充分,可导致以WEB进程权限在系统上执行任意指令。 不过这个漏洞只存在安装了RaQ4加固安全包之后的RaQ4服务程序中。
CVSS Information
N/A
Vulnerability Type
N/A