vendor:
SuSE Support Data Base
by:
Unknown
7.5
CVSS
HIGH
Input Validation Error
20
CWE
Product Name: SuSE Support Data Base
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: No
Related CWE: Unknown
CPE: a:suse:sdb
Platforms Tested:
Unknown
Input Validation Error in sdbsearch.cgi script
An input validation error exists in sdb, the SuSE Support Data Base. The problem exists in the sdbsearch.cgi script, which uses data directly from the 'Referer' header field from a HTTP request as a path when opening its 'keylist.txt' file. If an attacker is able to create a malicious 'keylist.txt' file on a vulnerable host, it may be possible for the attacker to cause arbitrary commands to be executed by the sdbsearch.cgi script.
Mitigation:
Implement proper input validation and sanitization checks in the sdbsearch.cgi script to prevent unauthorized command execution.