漏洞类别:Information gathering
漏洞等级:
漏洞信息
The shell can sometimes correct the spelling of filenames, commands and variable names as well as completing and listing them.
When spelling correction is invoked and the shell thinks that any part of the command line is misspelled, it prompts with the corrected line. Example: set correct = cmd > snort -V CORRECT>sort -V (y|n|e|a)?
It will wait for user interaction and after some time qid will timeout. If this occurs multiple times in the same scan, entire module will timeout leading to scan to discontinue.
漏洞危害
解决方案
Disable the spell correction by setting the 'correct' environment variable to appropriate value.
0day
文章评论