CVE-2012-5520

The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openvas:openvas_manager:3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta4:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta6:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta7:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:beta8:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:openvas:openvas_manager:3.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:44

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2012-11/0047.html - () http://archives.neohapsis.com/archives/bugtraq/2012-11/0047.html -
References () http://archives.neohapsis.com/archives/bugtraq/2012-11/0055.html - () http://archives.neohapsis.com/archives/bugtraq/2012-11/0055.html -
References () http://archives.neohapsis.com/archives/bugtraq/2012-11/0059.html - () http://archives.neohapsis.com/archives/bugtraq/2012-11/0059.html -
References () http://openwall.com/lists/oss-security/2012/11/13/12 - () http://openwall.com/lists/oss-security/2012/11/13/12 -
References () http://openwall.com/lists/oss-security/2012/11/13/9 - () http://openwall.com/lists/oss-security/2012/11/13/9 -
References () http://openwall.com/lists/oss-security/2012/11/14/11 - () http://openwall.com/lists/oss-security/2012/11/14/11 -
References () http://openwall.com/lists/oss-security/2012/11/14/5 - () http://openwall.com/lists/oss-security/2012/11/14/5 -
References () http://secunia.com/advisories/49128 - () http://secunia.com/advisories/49128 -
References () http://wald.intevation.org/scm/viewvc.php?view=rev&root=openvas&revision=14437 - () http://wald.intevation.org/scm/viewvc.php?view=rev&root=openvas&revision=14437 -
References () http://www.openvas.org/OVSA20121112.html - Exploit, Patch, Vendor Advisory () http://www.openvas.org/OVSA20121112.html - Exploit, Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/56497 - () http://www.securityfocus.com/bid/56497 -

Information

Published : 2012-11-26 12:45

Updated : 2025-04-11 00:51


NVD link : CVE-2012-5520

Mitre link : CVE-2012-5520

CVE.ORG link : CVE-2012-5520


JSON object : View

Products Affected

openvas

  • openvas_manager
CWE
CWE-20

Improper Input Validation