>> Novell Forum Unspecified Remote Tcl Code Execution Vulnerability
Title : Novell Forum Unspecified Remote Tcl Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-2465 CVE ID : CVE-2008-4047 CWE ID : CWE-20
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-01
Technical Description
A vulnerability has been identified in Novell Forum, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an unspecified input validation error, which could allow remote unauthenticated attackers to inject and execute arbitrary Tcl code via a specially crafted URL.