GREED GRX File List Command Execution Vulnerability
BID:12034
Info
GREED GRX File List Command Execution Vulnerability
| Bugtraq ID: | 12034 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Discovery is credited to Manigandan Radhakrishnan. |
| Vulnerable: |
greed greed 0.81 p |
| Not Vulnerable: | |
Discussion
GREED GRX File List Command Execution Vulnerability
greed (Get and Resume Elite Edition) is prone to unauthorized command execution. This issue is exposed when the application processes a GRX file list that specifies shell metacharacters and commands in file names on the list. GRX file lists allow file downloads to be scripted. Since GRX file lists may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation will result in command execution in the context of the application.
greed (Get and Resume Elite Edition) is prone to unauthorized command execution. This issue is exposed when the application processes a GRX file list that specifies shell metacharacters and commands in file names on the list. GRX file lists allow file downloads to be scripted. Since GRX file lists may originate from an external or untrusted source, this vulnerability is considered to be remote in nature.
Successful exploitation will result in command execution in the context of the application.
Exploit / POC
GREED GRX File List Command Execution Vulnerability
The following exploit example was published:
The following exploit example was published:
Solution / Fix
GREED GRX File List Command Execution Vulnerability
Solution:
greed is no longer maintained so it is not likely that the vendor will release fixes. Users should consider migrating to another application that is actively maintained.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
greed is no longer maintained so it is not likely that the vendor will release fixes. Users should consider migrating to another application that is actively maintained.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GREED GRX File List Command Execution Vulnerability
References:
References:
- [remote] [control] greed 0.81p DownloadLoop overflows COMMAND; DownloadLoop does ("D. J. Bernstein"
) - greed Homepage (greed)