MidnightBSD

Advisories for astrocam

CVE-2002-1874 HIGH

astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
astrocam astrocam 1.0.1
astrocam astrocam 0.9-1-1
astrocam astrocam 0.9-7-3
astrocam astrocam 1.4
astrocam astrocam 0.9-5-1
CVE-2007-1426 HIGH

The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
astrocam astrocam 2.6.1
astrocam astrocam 2.6.3
astrocam astrocam 2.6.4
astrocam astrocam 2.6.5
astrocam astrocam 2.6.0
astrocam astrocam 2.6.2
CVE-2008-2075 MEDIUM

Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0 through 2.7.3 allows remote attackers to inject arbitrary web script or HTML via the picfile parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
astrocam astrocam 2.5.8
astrocam astrocam 2.5.2
astrocam astrocam 2.7.2
astrocam astrocam 2.6.4
astrocam astrocam 2.6.5
astrocam astrocam 2.6.0
astrocam astrocam 2.5.9
astrocam astrocam 2.6.6
astrocam astrocam 2.7.1
astrocam astrocam 2.6.2
astrocam astrocam 2.7.0
astrocam astrocam 2.6.1
astrocam astrocam 2.6.3
astrocam astrocam 2.5.5
astrocam astrocam 2.5.7
astrocam astrocam 2.5.4
astrocam astrocam 2.5.1
astrocam astrocam 2.5.0
astrocam astrocam 2.5.3
astrocam astrocam 2.7.3
astrocam astrocam 2.5.6