CVE-2008-1331
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 8.78% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- alcatel-lucent/omnipcx office
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29798Third Party Advisory
- http://www.securityfocus.com/archive/1/492383/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020082Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1057Permissions Required
- http://www1.alcatel-lucent.com/psirt/statements/2008001/OXOrexec.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41560Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5662Third Party Advisory, VDB Entry
- http://secunia.com/advisories/29798Third Party Advisory
- http://www.securityfocus.com/archive/1/492383/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020082Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1057Permissions Required
- http://www1.alcatel-lucent.com/psirt/statements/2008001/OXOrexec.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41560Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5662Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.