Remote Code Execution via Host-Based Authentication Bypass in TORQUE Resource Manager 3.0.1 and Earlier

Remote Code Execution via Host-Based Authentication Bypass in TORQUE Resource Manager 3.0.1 and Earlier

CVE-2011-2907 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.

Learn more about our Web Application Penetration Testing UK.