WWW Authorization Gateway Vulnerability
BID:152
Info
WWW Authorization Gateway Vulnerability
| Bugtraq ID: | 152 |
| Class: | Input Validation Error |
| CVE: |
CVE-1999-1436 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was reported to Bugtraq by Albert Nubdy <[email protected]> on July 8, 1998. |
| Vulnerable: |
Ray Chan WWW Authorization Gateway 0.1 |
| Not Vulnerable: | |
Discussion
WWW Authorization Gateway Vulnerability
A vulnerability exists in the WWW Authorization Gateway program written by Ray Chan. Version 1.0 fails to eliminate characters with special meaning to the shell prior to executing a command. As a result, an attacker can utilize certain characters to execute arbitrary commands on a system remotely, as whatever user invoked the cgi-bin.
A vulnerability exists in the WWW Authorization Gateway program written by Ray Chan. Version 1.0 fails to eliminate characters with special meaning to the shell prior to executing a command. As a result, an attacker can utilize certain characters to execute arbitrary commands on a system remotely, as whatever user invoked the cgi-bin.
Exploit / POC
WWW Authorization Gateway Vulnerability
Place the following as a username:
| some command
and any password. The command will be executed.
Place the following as a username:
| some command
and any password. The command will be executed.