[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-4495Date: (C)2013-11-28   (M)2023-12-22


The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-55535
SECUNIA-55622
DSA-2796
https://www.adaptivecomputing.com/wp-content/uploads/releasenotes/releaseNotes-4.2.6.html

CPE    75
cpe:/a:adaptivecomputing:torque_resource_manager:2.2.0
cpe:/a:adaptivecomputing:torque_resource_manager:2.2.1
cpe:/a:adaptivecomputing:torque_resource_manager:2.0.0
cpe:/a:adaptivecomputing:torque_resource_manager:3.0.6
...
CWE    1
CWE-94
OVAL    6
oval:org.secpod.oval:def:109137
oval:org.secpod.oval:def:107825
oval:org.secpod.oval:def:109124
oval:org.secpod.oval:def:107816
...

© SecPod Technologies