The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Domain_technologie_control | Gplhost | * | 0.32.7 (including) |
Domain_technologie_control | Gplhost | 0.24.6 (including) | 0.24.6 (including) |
Domain_technologie_control | Gplhost | 0.25.1 (including) | 0.25.1 (including) |
Domain_technologie_control | Gplhost | 0.25.2 (including) | 0.25.2 (including) |
Domain_technologie_control | Gplhost | 0.25.3 (including) | 0.25.3 (including) |
Domain_technologie_control | Gplhost | 0.26.7 (including) | 0.26.7 (including) |
Domain_technologie_control | Gplhost | 0.26.8 (including) | 0.26.8 (including) |
Domain_technologie_control | Gplhost | 0.26.9 (including) | 0.26.9 (including) |
Domain_technologie_control | Gplhost | 0.27.3 (including) | 0.27.3 (including) |
Domain_technologie_control | Gplhost | 0.28.2 (including) | 0.28.2 (including) |
Domain_technologie_control | Gplhost | 0.28.3 (including) | 0.28.3 (including) |
Domain_technologie_control | Gplhost | 0.28.4 (including) | 0.28.4 (including) |
Domain_technologie_control | Gplhost | 0.28.6 (including) | 0.28.6 (including) |
Domain_technologie_control | Gplhost | 0.28.9 (including) | 0.28.9 (including) |
Domain_technologie_control | Gplhost | 0.28.10 (including) | 0.28.10 (including) |
Domain_technologie_control | Gplhost | 0.29.1 (including) | 0.29.1 (including) |
Domain_technologie_control | Gplhost | 0.29.6 (including) | 0.29.6 (including) |
Domain_technologie_control | Gplhost | 0.29.8 (including) | 0.29.8 (including) |
Domain_technologie_control | Gplhost | 0.29.10 (including) | 0.29.10 (including) |
Domain_technologie_control | Gplhost | 0.29.14 (including) | 0.29.14 (including) |
Domain_technologie_control | Gplhost | 0.29.15 (including) | 0.29.15 (including) |
Domain_technologie_control | Gplhost | 0.29.16 (including) | 0.29.16 (including) |
Domain_technologie_control | Gplhost | 0.29.17 (including) | 0.29.17 (including) |
Domain_technologie_control | Gplhost | 0.30.6 (including) | 0.30.6 (including) |
Domain_technologie_control | Gplhost | 0.30.8 (including) | 0.30.8 (including) |
Domain_technologie_control | Gplhost | 0.30.10 (including) | 0.30.10 (including) |
Domain_technologie_control | Gplhost | 0.30.18 (including) | 0.30.18 (including) |
Domain_technologie_control | Gplhost | 0.30.20 (including) | 0.30.20 (including) |
Domain_technologie_control | Gplhost | 0.32.1 (including) | 0.32.1 (including) |
Domain_technologie_control | Gplhost | 0.32.2 (including) | 0.32.2 (including) |
Domain_technologie_control | Gplhost | 0.32.3 (including) | 0.32.3 (including) |
Domain_technologie_control | Gplhost | 0.32.4 (including) | 0.32.4 (including) |
Domain_technologie_control | Gplhost | 0.32.5 (including) | 0.32.5 (including) |
Domain_technologie_control | Gplhost | 0.32.6 (including) | 0.32.6 (including) |
Dtc | Ubuntu | lucid | * |