Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-1868
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1868

Description:
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

CVE Status:
Candidate

References:

ST
  1017840

SAID
  Secunia Advisory: SA24717

MISC
  http://www-1.ibm.com/support/docview.wss?uid=swg24015347

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=498

BID
  23264


Return to the previous page.