vendor:
DB2TEST Database
by:
Dennis Yurichev
7.5
CVSS
HIGH
Remote Code Execution
Unknown
CWE
Product Name: DB2TEST Database
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
DB2TEST Database Remote Code Execution
This exploit allows an attacker to execute arbitrary code on a target system running the DB2TEST database. The exploit requires the presence of a GUEST account with the password QQ on the target system. It sends a specially crafted payload to the target system's port 50000 to execute the code.
Mitigation:
To mitigate this vulnerability, ensure that the DB2TEST database is not present on the target system and remove the GUEST account with the password QQ from the system. Additionally, apply any patches or updates provided by the vendor to address this vulnerability.