Looking Glass Remote Command Execution Vulnerability
BID:14682
Info
Looking Glass Remote Command Execution Vulnerability
| Bugtraq ID: | 14682 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2005 12:00AM |
| Updated: | Aug 27 2005 12:00AM |
| Credit: | Discovery is credited to rgod <[email protected]>. |
| Vulnerable: |
Looking Glass Looking Glass |
| Not Vulnerable: | |
Discussion
Looking Glass Remote Command Execution Vulnerability
Looking Glass may be exploited to execute arbitrary commands.
An attacker can prefix arbitrary commands with the '|' character, supply them through a URI parameter and have them executed in the context of the server.
This can facilitate unauthorized remote access.
Looking Glass may be exploited to execute arbitrary commands.
An attacker can prefix arbitrary commands with the '|' character, supply them through a URI parameter and have them executed in the context of the server.
This can facilitate unauthorized remote access.
Exploit / POC
Looking Glass Remote Command Execution Vulnerability
An exploit is not required.
A proof of concept example is available:
An exploit is not required.
A proof of concept example is available:
Solution / Fix
Looking Glass Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Looking Glass Remote Command Execution Vulnerability
References:
References: