vendor:
Services for Unix
by:
Unknown
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Services for Unix
Affected Version From: Services for Unix 2.0
Affected Version To: Services for Unix 2.0
Patch Exists: NO
Related CWE: CVE-2001-0543
CPE: a:microsoft:services_for_unix:2.0
Platforms Tested:
Unknown
Services for Unix 2.0 Telnet Client Command Execution Vulnerability
A vulnerability exists in Services for Unix 2.0 that allows a remote user to execute arbitrary commands on a target machine by crafting a URL with command line parameters to the telnet client. The telnet client initiates the logging of session information, allowing an attacker to write and execute arbitrary commands.
Mitigation:
Apply the necessary patches or updates from the vendor to fix this vulnerability. Additionally, disable the client side logging option in Services for Unix 2.0.