Menu Manager Module System Command Remote Command Execution Vulnerability
BID:24453
Info
Menu Manager Module System Command Remote Command Execution Vulnerability
| Bugtraq ID: | 24453 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3242 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | [email protected] is credited with discovering this vulnerability. |
| Vulnerable: |
Web-APP.org WebAPP 0.9.9.5 Web-APP.org WebAPP 0.9.9.4 Web-APP.org WebAPP 0.9.9.3.5 Web-APP.org WebAPP 0.9.9.3.2 Web-APP.org WebAPP 0.9.9.3 Web-APP.org WebAPP 0.9.9.2 Web-APP.org WebAPP 0.9.9.1 Web-APP.net WebAPP NE 0.9.9.3.4 Web-APP.net WebAPP NE 0.9.9.3.3 2xInt Menu Manager Module 1.5 |
| Not Vulnerable: |
Web-APP.org WebAPP 0.9.9.6 Web-APP.net WebAPP NE 2007 |
Discussion
Menu Manager Module System Command Remote Command Execution Vulnerability
The Menu Manager module for WebAPP is prone to a remote command-execution vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary system commands within the context of the affected webserver.
This issue affects Menu Manager Module 1.5 running on WebAPP prior to 0.9.9.7.
The Menu Manager module for WebAPP is prone to a remote command-execution vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary system commands within the context of the affected webserver.
This issue affects Menu Manager Module 1.5 running on WebAPP prior to 0.9.9.7.
Exploit / POC
Menu Manager Module System Command Remote Command Execution Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Menu Manager Module System Command Remote Command Execution Vulnerability
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on obtaining upgrades.
2xInt Menu Manager Module 1.5
Solution:
The vendor released an update to address this issue. Please contact the vendor for information on obtaining upgrades.
2xInt Menu Manager Module 1.5
-
2xInt Menu Manager patch
http://www.web-app.net/cgi-bin/index.cgi?action=redirectd&cat=security &id=3
References
Menu Manager Module System Command Remote Command Execution Vulnerability
References:
References: