astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| astrocam | astrocam | 1.0.1 |
| astrocam | astrocam | 0.9-1-1 |
| astrocam | astrocam | 0.9-7-3 |
| astrocam | astrocam | 1.4 |
| astrocam | astrocam | 0.9-5-1 |
The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue."
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| astrocam | astrocam | 2.6.1 |
| astrocam | astrocam | 2.6.3 |
| astrocam | astrocam | 2.6.4 |
| astrocam | astrocam | 2.6.5 |
| astrocam | astrocam | 2.6.0 |
| astrocam | astrocam | 2.6.2 |
Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0 through 2.7.3 allows remote attackers to inject arbitrary web script or HTML via the picfile parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| astrocam | astrocam | 2.5.8 |
| astrocam | astrocam | 2.5.2 |
| astrocam | astrocam | 2.7.2 |
| astrocam | astrocam | 2.6.4 |
| astrocam | astrocam | 2.6.5 |
| astrocam | astrocam | 2.6.0 |
| astrocam | astrocam | 2.5.9 |
| astrocam | astrocam | 2.6.6 |
| astrocam | astrocam | 2.7.1 |
| astrocam | astrocam | 2.6.2 |
| astrocam | astrocam | 2.7.0 |
| astrocam | astrocam | 2.6.1 |
| astrocam | astrocam | 2.6.3 |
| astrocam | astrocam | 2.5.5 |
| astrocam | astrocam | 2.5.7 |
| astrocam | astrocam | 2.5.4 |
| astrocam | astrocam | 2.5.1 |
| astrocam | astrocam | 2.5.0 |
| astrocam | astrocam | 2.5.3 |
| astrocam | astrocam | 2.7.3 |
| astrocam | astrocam | 2.5.6 |