I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
BID:10626
Info
I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
| Bugtraq ID: | 10626 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2004 12:00AM |
| Updated: | Jun 29 2004 12:00AM |
| Credit: | Discovery is credited to ZetaLabs, Zone-H Laboratories. |
| Vulnerable: |
I-Mall Commerce i-mall.cgi |
| Not Vulnerable: | |
Discussion
I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
i-mall.cgi is reported prone to a remote arbitrary command execution vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data and may allow a remote attacker to pass arbitrary shell commands to the vulnerable script.
i-mall.cgi is reported prone to a remote arbitrary command execution vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data and may allow a remote attacker to pass arbitrary shell commands to the vulnerable script.
Exploit / POC
I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
No exploit is required.
The following proof of concept is available:
No exploit is required.
The following proof of concept is available:
Solution / Fix
I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
I-Mall Commerce I-mall Script Remote Command Execution Vulnerability
References:
References: