vendor:
Simple Unix MONitor
by:
dun
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Simple Unix MONitor
Affected Version From: 0.7.0
Affected Version To: 0.7.0
Patch Exists: YES
Related CWE: N/A
CPE: a:sumon:sumon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
sumon <= 0.7.0 Remote Command Execution Vulnerability
A vulnerability exists in Simple Unix MONitor (sumon) version 0.7.0, which allows remote attackers to execute arbitrary commands via the host parameter in chg.php, the host parameter in stats.php, and the fichero_post parameter in showfile.php and difffile.php.
Mitigation:
Upgrade to version 0.7.1