TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
BID:14960
Info
TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14960 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2877 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | JChristophFuchs <[email protected]> and JoseLuna <[email protected]> disclosed this issue to the vendor. |
| Vulnerable: |
TWiki TWiki 20040903 TWiki TWiki 20040902 TWiki TWiki 20040901 TWiki TWiki 20030201 TWiki TWiki 01-Dec-2001 |
| Not Vulnerable: | |
Discussion
TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
A remote command execution vulnerability affects the application.
The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line. An attacker may use a specially crafted URI to execute arbitrary commands through the shell.
This attack would occur in the context of the vulnerable application and can facilitate unauthorized remote access.
A remote command execution vulnerability affects the application.
The revision control function of the TWikiUsers script uses the backtick shell metacharacter to construct a command line. An attacker may use a specially crafted URI to execute arbitrary commands through the shell.
This attack would occur in the context of the vulnerable application and can facilitate unauthorized remote access.
Exploit / POC
TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
An exploit is not required.
The following proof of concept example is available:
%INCLUDE{ "Main.TWikiUsers" rev="2|less /etc/passwd" }%
An exploit is not required.
The following proof of concept example is available:
%INCLUDE{ "Main.TWikiUsers" rev="2|less /etc/passwd" }%
Solution / Fix
TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for further information.
A patch addressing this issue has been made available at:
http://twiki.org/cgi-bin/view/Codev/UncoordinatedSecurityAlert23Feb2005
TWiki TWiki 20040902
Solution:
The vendor has released an advisory to address this issue. Please see the referenced advisory for further information.
A patch addressing this issue has been made available at:
http://twiki.org/cgi-bin/view/Codev/UncoordinatedSecurityAlert23Feb2005
TWiki TWiki 20040902
-
TWiki TWiki200409-02-03.patch
http://twiki.org/p/pub/Codev/SecurityAlertExecuteCommandsWithRev/TWiki 200409-02-03.patch
References
TWiki TWikiUsers INCLUDE Function Remote Arbitrary Command Execution Vulnerability
References:
References:
- Hotfix 2 for TWiki 4.0.4 (TWiki)
- TWiki Configure Script "TYPEOF" Parameter Handling Remote Command Injection Vuln (FrSIRT)
- TWiki Homepage (TWiki)
- TWiki Security Alerts (TWiki)