TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
BID:14834
Info
TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14834 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2877 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | This issue was reported by B4dP4nd4 <[email protected]>. |
| Vulnerable: |
TWiki TWiki 20040902 TWiki TWiki 20040901 TWiki TWiki 20030201 TWiki TWiki 01-Dec-2001 |
| Not Vulnerable: | |
Discussion
TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
A remote command execution vulnerability affects the application.
The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line. An attacker may use a specially crafted URI to execute arbitrary commands through the shell.
This attack would occur in the context of the vulnerable application and can facilitate unauthorized remote access.
A remote command execution vulnerability affects the application.
The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line. An attacker may use a specially crafted URI to execute arbitrary commands through the shell.
This attack would occur in the context of the vulnerable application and can facilitate unauthorized remote access.
Exploit / POC
TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/cgi-bin/view/Main/TWikiUsers?rev=2%20%7Cless%20/etc/passwd
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/cgi-bin/view/Main/TWikiUsers?rev=2%20%7Cless%20/etc/passwd
Solution / Fix
TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
Solution:
The vendor has released a patch to address this issue.
Patches for released prior to TWiki 20040902 are also available from the following location:
http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithRev
TWiki TWiki 20040902
Solution:
The vendor has released a patch to address this issue.
Patches for released prior to TWiki 20040902 are also available from the following location:
http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithRev
TWiki TWiki 20040902
-
TWiki TWiki200409-02-03.patch
http://twiki.org/p/pub/Codev/SecurityAlertExecuteCommandsWithRev/TWiki 200409-02-03.patch
References
TWiki TWikiUsers Remote Arbitrary Command Execution Vulnerability
References:
References: