CORE IMPACT v12 - Exploits Update (Tue Oct 25 2011)
Samba Username Map Script Command Injection Exploit
Exploits/Remote [Linux]
Tue Oct 25 2011
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the SamrChangePassword function, when the "username map script" smb.conf option is enabled.
Exploits Vulnerabiltiy: CVE-2007-2447











