Pete Stein GoScript Remote Command Execution Vulnerability
BID:10853
Info
Pete Stein GoScript Remote Command Execution Vulnerability
| Bugtraq ID: | 10853 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-2776 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Discovery is credited to Francisco Alisson. |
| Vulnerable: |
Pete Stein GoScript 2.0 |
| Not Vulnerable: | |
Discussion
Pete Stein GoScript Remote Command Execution Vulnerability
Pete Stein GoScript is prone to a remote command execution vulnerability.
This may allow remote attackers to perform unauthorized actions on a victim computer in the context of the hosting Web server.
Pete Stein GoScript is prone to a remote command execution vulnerability.
This may allow remote attackers to perform unauthorized actions on a victim computer in the context of the hosting Web server.
Exploit / POC
Pete Stein GoScript Remote Command Execution Vulnerability
The following examples were submitted:
http://www.example.com/go.cgi?|id|
http://www.example.com/go.cgi?artarchive=|id|
The following examples were submitted:
http://www.example.com/go.cgi?|id|
http://www.example.com/go.cgi?artarchive=|id|
Solution / Fix
Pete Stein GoScript Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pete Stein GoScript Remote Command Execution Vulnerability
References:
References:
- Re: CVE request: monitorix: HTTP server 'handle_request()' session fixation & XS (SecLists.Org)
- Vendor Homepage (Pete Stein)
- GoScript Remote Command Execution (Francisco Alisson
)