>> Jinzora "httpsrequest" Function Remote Command Execution Issue
Title : Jinzora "httpsrequest" Function Remote Command Execution Issue VUPEN ID : VUPEN/ADV-2005-2727 CVE ID : CVE-2005-3330
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-05
Technical Description
A vulnerability has been identified in Jinzora, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an input validation error in the "_httpsrequest" function of Snoopy when passing malformed URLs to the "exec()" call, which could be exploited by remote attackers to execute arbitrary commands via a specially crafted URL. For additional information, see : VUPEN/ADV-2005-2202