Arbitrary Command Execution via SMS Server Tools (SMStools)

Arbitrary Command Execution via SMS Server Tools (SMStools)

CVE-2002-0437 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.

Learn more about our Cis Benchmark Audit For Server Software.