Description
|
|
Multiple vulnerabilities have been identified in IP3 Networks NA75, which could be exploited by attackers or malicious users to execute arbitrary commands or gain knowledge sensitive information.
The first issue is due to input validation errors in the web interface that does not validate certain parameters, which could be exploited by malicious people to conduct SQL injection attacks.
The second flaw is due to input validation errors in the command line interface, which could be exploited by attackers to inject arbitrary shell commands via the backtick character.
The third issue is due to insecure permissions (world-readable) being set on the shadow password, which could be exploited by malicious users to disclose sensitive information.
The fourth flaw is due to insecure permissions (world-readable and world-writable) being set on the database file, which could be exploited by malicious users to gain knowledge sensitive information.
|