CVE-2005-2259

UnknownEPSS 4.23%

Last modified

CVE-2005-2259 is a vulnerability of currently unknown severity. The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.. EPSS estimates a 4.23% chance of exploitation in the next 30 days.

Description

The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.

Metrics

EPSS Probability
4.23%

89.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Usanet CreationsDomain Name AuctionAll versions
Usanet CreationsMakebid Auction DeluxeAll versions
Usanet CreationsMakebid Auction Deluxe3.30
Usanet CreationsMakebid Auction StandardAll versions
Usanet CreationsMakebid Reverse AuctionAll versions
Usanet CreationsStandard Classified AdsAll versions
Usanet CreationsUsanet Shopping MallAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-2259?
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.
How severe is CVE-2005-2259?
Severity scoring for CVE-2005-2259 is pending analysis. The EPSS model estimates a 4.23% probability of exploitation in the next 30 days.
How do I fix CVE-2005-2259?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-2259?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST