Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hans Persson Molly多个远程命令执行漏洞
Vulnerability Description
Molly是小型简单的IRC BOT程序,可以用于股票信息查询,投票等操作。 Molly中多个脚本对用户提交的参数缺少正确检查,远程攻击者可以利用这个漏洞以WEB进程权限在系统上执行任意命令。 plugins/nslookup.pl脚本中在调用SHELL时对用户参数的输入缺少正确过滤,如果用户提交的'$host'变量包SHELL元字符加命令(如scan-associates.net;/bin/ls),可导致命令以WEB权限执行。 另外unusedplugins/pop.pl和unusedplugins/s
CVSS Information
N/A
Vulnerability Type
N/A