Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-0904

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2002-0904
Last Modified 05 Sep 2008 04:29:15
Published 04 Oct 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2002-0904

Summary

SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.

Vulnerable Systems

Application

  • Kismet 2.2

  • Kismet 2.2.1


References

BID - 4883

XF - kismet-saytext-command-execution(9213)

CONFIRM - http://www.kismetwireless.net/CHANGELOG

VULN-DEV - 20020529 New Kismet Packages available - SayText() and suid kismet_server issues

BUGTRAQ - 20020528 New Kismet Packages available - SayText() and suid kismet_server issues


Last Updated: 27 May 2016 10:37:07