PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
BID:14601
Info
PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14601 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2005 12:00AM |
| Updated: | Aug 18 2005 12:00AM |
| Credit: | rgod is credit with the discovery of this vulnerability. |
| Vulnerable: |
PHPOutsourcing Zorum 3.5 |
| Not Vulnerable: | |
Discussion
PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
Zorum is prone to an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
This issue may facilitate unauthorized remote access in the context of the Web server to the affected computer.
Zorum is prone to an arbitrary command execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
This issue may facilitate unauthorized remote access in the context of the Web server to the affected computer.
Exploit / POC
PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/zorum/gorum/prod.php?argv[1]=|cat%20/etc/passwd
rgod has supplied the following exploit:
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/zorum/gorum/prod.php?argv[1]=|cat%20/etc/passwd
rgod has supplied the following exploit:
Solution / Fix
PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPOutsourcing Zorum Prod.PHP Arbitrary Command Execution Vulnerability
References:
References:
- Zorum Home Page (PHPOutsourcing)
- Zorum 3.5 remote code execution poc exploit ([email protected])