GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
BID:14148
Info
GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
| Bugtraq ID: | 14148 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 05 2005 12:00AM |
| Credit: | Discovery is credited to Nicola (AcidCrash) Ballotta. |
| Vulnerable: |
GlobalNoteScript GlobalNoteScript 4.20 |
| Not Vulnerable: | |
Discussion
GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
GlobalNoteScript is prone to a remote arbitrary command execution vulnerability.
Reportedly, this issue arises when the user-specified 'file' URI parameter of the 'read.cgi' script is supplied to the Perl open() routine.
This issue may facilitate unauthorized remote access in the context of the Web server to the affected computer.
GlobalNoteScript 4.20 and prior versions are affected.
GlobalNoteScript is prone to a remote arbitrary command execution vulnerability.
Reportedly, this issue arises when the user-specified 'file' URI parameter of the 'read.cgi' script is supplied to the Perl open() routine.
This issue may facilitate unauthorized remote access in the context of the Web server to the affected computer.
GlobalNoteScript 4.20 and prior versions are affected.
Exploit / POC
GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
An exploit is not required.
The following proof of concept is available:
http://www.example.com/cgi-bin/bbs/read.cgi?file=|uname%20-a|&bbs_id=00001
An exploit is not required.
The following proof of concept is available:
http://www.example.com/cgi-bin/bbs/read.cgi?file=|uname%20-a|&bbs_id=00001
Solution / Fix
GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GlobalNoteScript Read.CGI Remote Command Execution Vulnerability
References:
References: