Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
BID:10637
Info
Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
| Bugtraq ID: | 10637 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2004 12:00AM |
| Updated: | Jun 30 2004 12:00AM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
Open Webmail Open Webmail 2.32 Open Webmail Open Webmail 2.31 Open Webmail Open Webmail 2.30 Open Webmail Open Webmail 2.21 Open Webmail Open Webmail 2.20 Open Webmail Open Webmail 1.90 Open Webmail Open Webmail 1.81 Open Webmail Open Webmail 1.71 Open Webmail Open Webmail 1.8 Open Webmail Open Webmail 1.7 |
| Not Vulnerable: | |
Discussion
Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
A vulnerability is reported in Open WebMail that allows a remote attacker to execute arbitrary commands on a vulnerable host.
Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.
This vulnerability is reported to affect all versions of Open WebMail released before 29/06/2004.
A vulnerability is reported in Open WebMail that allows a remote attacker to execute arbitrary commands on a vulnerable host.
Exploitation of the vulnerability could allow a non-privileged user to remotely execute arbitrary commands in the context of the web server that is hosting the vulnerable application.
This vulnerability is reported to affect all versions of Open WebMail released before 29/06/2004.
Exploit / POC
Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
Solution:
The vendor has released a patch to address this issue:
http://downloads.securityfocus.com/vulnerabilities/patches/vacation.pl.patch
Alternatively the patch is available at the following location:
Open Webmail Open Webmail 1.7
Open Webmail Open Webmail 1.71
Open Webmail Open Webmail 1.8
Open Webmail Open Webmail 1.81
Open Webmail Open Webmail 1.90
Open Webmail Open Webmail 2.20
Open Webmail Open Webmail 2.21
Open Webmail Open Webmail 2.30
Open Webmail Open Webmail 2.31
Open Webmail Open Webmail 2.32
Solution:
The vendor has released a patch to address this issue:
http://downloads.securityfocus.com/vulnerabilities/patches/vacation.pl.patch
Alternatively the patch is available at the following location:
Open Webmail Open Webmail 1.7
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 1.71
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 1.8
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 1.81
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 1.90
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 2.20
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 2.21
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 2.30
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 2.31
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
Open Webmail Open Webmail 2.32
-
Open WebMail vacation.pl.patch
http://openwebmail.org/openwebmail/download/cert/patches/SA-04:04/vaca tion.pl.patch
References
Open WebMail Vacation.PL Remote Command Execution Variant Vulnerability
References:
References:
- Open Webmail Homepage (Open Webmail)
- Product Changelog (Open WebMail)
- Security Advisory 20040629 (Open WebMail - openwebmail)