PineApp Mail-SeCure 'test _ li_connection.php 'Remote Command Injection Vulnerability
Release date:
Updated on: 2013-07-30
Affected Systems:
PineApp Mail-SeCure Series
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61477
PineApp Mail-SeCure is a security solution for network and Mail systems.
The PineApp Mail-SeCure series 'test _ li_connection.php 'component has a vulnerability in certificate installation. It allows authenticated remote attackers to inject arbitrary commands into the server, then execute these commands with root permissions.
<* Source: anonymous
Dave Weinstein
Link: http://www.securelist.com/en/advisories/54342
Http://secunia.com/advisories/54342/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PineApp
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www2.pineapp.com/