漏洞描述
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/felmoltor↗packetstormsecurity.comhttp://packetstormsecurity.com/files/160809/SpamTitan-7.07-Command-Injection.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/159470/SpamTitan-7.07-Remote-Code-Execution.html↗twitter.comhttps://twitter.com/felmoltor↗www.spamtitan.comhttps://www.spamtitan.com/↗sensepost.comhttps://sensepost.com/blog/2020/clash-of-the-spamtitan/↗