xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
| Software | From | Fixed in |
|---|---|---|
| xymon / xymon | 4.2-alfa | 4.2-alfa.x |
| xymon / xymon | 4.3.0-rc1 | 4.3.0-rc1.x |
| xymon / xymon | 4.3.18 | 4.3.18.x |
| xymon / xymon | 4.3.13 | 4.3.13.x |
| xymon / xymon | 4.3.21 | 4.3.21.x |
| xymon / xymon | 4.3.8 | 4.3.8.x |
| xymon / xymon | 4.3.3 | 4.3.3.x |
| xymon / xymon | 4.1.1 | 4.1.1.x |
| xymon / xymon | 4.2-rc20060712 | 4.2-rc20060712.x |
| xymon / xymon | 4.2.2-rc1 | 4.2.2-rc1.x |
| xymon / xymon | 4.3.4 | 4.3.4.x |
| xymon / xymon | 4.3.17 | 4.3.17.x |
| xymon / xymon | 4.3.22 | 4.3.22.x |
| xymon / xymon | 4.2.2 | 4.2.2.x |
| xymon / xymon | 4.3.15 | 4.3.15.x |
| xymon / xymon | 4.3.14 | 4.3.14.x |
| xymon / xymon | 4.2.3-rc1 | 4.2.3-rc1.x |
| xymon / xymon | 4.3.0 | 4.3.0.x |
| xymon / xymon | 4.3.24 | 4.3.24.x |
| xymon / xymon | 4.3.20 | 4.3.20.x |
| xymon / xymon | 4.3.10 | 4.3.10.x |
| xymon / xymon | 4.2.3 | 4.2.3.x |
| xymon / xymon | 4.3.0-beta3 | 4.3.0-beta3.x |
| xymon / xymon | 4.3.1 | 4.3.1.x |
| xymon / xymon | 4.3.0-beta2 | 4.3.0-beta2.x |
| xymon / xymon | 4.1.0 | 4.1.0.x |
| xymon / xymon | 4.1.2-p1 | 4.1.2-p1.x |
| xymon / xymon | 4.2-beta20060605 | 4.2-beta20060605.x |
| xymon / xymon | 4.3.7 | 4.3.7.x |
| xymon / xymon | 4.2.0 | 4.2.0.x |
| xymon / xymon | 4.3.11 | 4.3.11.x |
| xymon / xymon | 4.3.12 | 4.3.12.x |
| xymon / xymon | 4.3.5 | 4.3.5.x |
| xymon / xymon | 4.3.0-beta1 | 4.3.0-beta1.x |
| xymon / xymon | 4.3.16 | 4.3.16.x |
| xymon / xymon | 4.1.2 | 4.1.2.x |
| xymon / xymon | 4.1.2-p2 | 4.1.2-p2.x |
| xymon / xymon | 4.3.6 | 4.3.6.x |
| xymon / xymon | 4.3.19 | 4.3.19.x |
| xymon / xymon | 4.3.23 | 4.3.23.x |
| xymon / xymon | 4.3.2 | 4.3.2.x |
| xymon / xymon | 4.3.19-rc1 | 4.3.19-rc1.x |
| xymon / xymon | 4.3.9 | 4.3.9.x |
| debian / debian_linux | 8.0 | 8.0.x |