CVE Vulnerabilities

CVE-2011-5274

Published: Mar 21, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

Affected Software

Name Vendor Start Version End Version
Domain_technologie_control Gplhost * 0.32.7 (including)
Domain_technologie_control Gplhost 0.24.6 (including) 0.24.6 (including)
Domain_technologie_control Gplhost 0.25.1 (including) 0.25.1 (including)
Domain_technologie_control Gplhost 0.25.2 (including) 0.25.2 (including)
Domain_technologie_control Gplhost 0.25.3 (including) 0.25.3 (including)
Domain_technologie_control Gplhost 0.26.7 (including) 0.26.7 (including)
Domain_technologie_control Gplhost 0.26.8 (including) 0.26.8 (including)
Domain_technologie_control Gplhost 0.26.9 (including) 0.26.9 (including)
Domain_technologie_control Gplhost 0.27.3 (including) 0.27.3 (including)
Domain_technologie_control Gplhost 0.28.2 (including) 0.28.2 (including)
Domain_technologie_control Gplhost 0.28.3 (including) 0.28.3 (including)
Domain_technologie_control Gplhost 0.28.4 (including) 0.28.4 (including)
Domain_technologie_control Gplhost 0.28.6 (including) 0.28.6 (including)
Domain_technologie_control Gplhost 0.28.9 (including) 0.28.9 (including)
Domain_technologie_control Gplhost 0.28.10 (including) 0.28.10 (including)
Domain_technologie_control Gplhost 0.29.1 (including) 0.29.1 (including)
Domain_technologie_control Gplhost 0.29.6 (including) 0.29.6 (including)
Domain_technologie_control Gplhost 0.29.8 (including) 0.29.8 (including)
Domain_technologie_control Gplhost 0.29.10 (including) 0.29.10 (including)
Domain_technologie_control Gplhost 0.29.14 (including) 0.29.14 (including)
Domain_technologie_control Gplhost 0.29.15 (including) 0.29.15 (including)
Domain_technologie_control Gplhost 0.29.16 (including) 0.29.16 (including)
Domain_technologie_control Gplhost 0.29.17 (including) 0.29.17 (including)
Domain_technologie_control Gplhost 0.30.6 (including) 0.30.6 (including)
Domain_technologie_control Gplhost 0.30.8 (including) 0.30.8 (including)
Domain_technologie_control Gplhost 0.30.10 (including) 0.30.10 (including)
Domain_technologie_control Gplhost 0.30.18 (including) 0.30.18 (including)
Domain_technologie_control Gplhost 0.30.20 (including) 0.30.20 (including)
Domain_technologie_control Gplhost 0.32.1 (including) 0.32.1 (including)
Domain_technologie_control Gplhost 0.32.2 (including) 0.32.2 (including)
Domain_technologie_control Gplhost 0.32.3 (including) 0.32.3 (including)
Domain_technologie_control Gplhost 0.32.4 (including) 0.32.4 (including)
Domain_technologie_control Gplhost 0.32.5 (including) 0.32.5 (including)
Domain_technologie_control Gplhost 0.32.6 (including) 0.32.6 (including)
Dtc Ubuntu lucid *

References