Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2483

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-2483
Last Modified 05 Sep 2008 04:51:52
Published 07 Aug 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-2483

Summary

Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.

Vulnerable Systems

Application

  • Karrigell 2.0

  • Karrigell 2.0 Beta

  • Karrigell 2.0.1

  • Karrigell 2.0.2

  • Karrigell 2.0.3

  • Karrigell 2.0.4

  • Karrigell 2.0.5

  • Karrigell 2.1

  • Karrigell 2.1.1

  • Karrigell 2.1.2

  • Karrigell 2.1.3

  • Karrigell 2.1.4

  • Karrigell 2.1.5


References

MLIST - [karrigell-main] 20050802 Re: SECURITY: python namespace exposure

SECUNIA - 16319

XF - karrigel-dos(21668)

BID - 14463

OSVDB - 18506

MLIST - [karrigell-main] 20050731 SECURITY: python namespace exposure


Last Updated: 27 May 2016 10:40:32