WeHelpBUS Remote Command Execution Vulnerability
BID:11431
Info
WeHelpBUS Remote Command Execution Vulnerability
| Bugtraq ID: | 11431 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2004 12:00AM |
| Updated: | Oct 15 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
WeHelpBUS WeHelpBUS 0.1 |
| Not Vulnerable: |
WeHelpBUS WeHelpBUS 0.2 |
Discussion
WeHelpBUS Remote Command Execution Vulnerability
WeHelpBUS is reported prone to a remote command execution vulnerability. This vulnerability is due to an input validation error that allows for the appending of shell commands in URI parameter data.
An attacker could leverage this issue to execute arbitrary shell commands on a vulnerable computer with the privileges of the web server process.
WeHelpBUS is reported prone to a remote command execution vulnerability. This vulnerability is due to an input validation error that allows for the appending of shell commands in URI parameter data.
An attacker could leverage this issue to execute arbitrary shell commands on a vulnerable computer with the privileges of the web server process.
Exploit / POC
WeHelpBUS Remote Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
WeHelpBUS Remote Command Execution Vulnerability
Solution:
The vendor has released an update to address this vulnerability:
WeHelpBUS WeHelpBUS 0.1
Solution:
The vendor has released an update to address this vulnerability:
WeHelpBUS WeHelpBUS 0.1
-
WeHelpBUS wehelpbus-0.2.tar.gz
http://prdownloads.sourceforge.net/wehelpbus/wehelpbus-0.2.tar.gz?down load
References
WeHelpBUS Remote Command Execution Vulnerability
References:
References:
- WeHelpBUS Homepage (WeHelpBUS)
- WeHelpBUS: Release Notes (WeHelpBUS)