DCForum 'AZ' Field Remote Command Execution Vulnerability
BID:2611
Info
DCForum 'AZ' Field Remote Command Execution Vulnerability
| Bugtraq ID: | 2611 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0436 CVE-2001-0437 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by Franklin DeMatto <[email protected]> on 17 Apr 2001 |
| Vulnerable: |
DC Scripts DCForum 2000 1.0 DC Scripts DCForum 6.0 DC Scripts DCForum 5.0 DC Scripts DCForum 4.0 DC Scripts DCForum 3.0 DC Scripts DCForum 2.0 DC Scripts DCForum 1.0 |
| Not Vulnerable: | |
Discussion
DCForum 'AZ' Field Remote Command Execution Vulnerability
DCForum is a commercial cgi script from DCScripts which is designed to facilitate web-based threaded discussion forums.
All versions of DCForum are vulnerable to remote execution of arbitrary commands.
DCForum fails to properly validate user-supplied input to the script. By inserting shell commands in submitted querystrings, an attacker can cause the script to open and parse commands in an external file on the target system.
By supplying a long path (containing '/../' sequences) an attacker can force the script to open a file from arbitrary locations on the filesystem. Commands in this file will be executed with the privilege level of the webserver - usually 'nobody'.
DCForum is a commercial cgi script from DCScripts which is designed to facilitate web-based threaded discussion forums.
All versions of DCForum are vulnerable to remote execution of arbitrary commands.
DCForum fails to properly validate user-supplied input to the script. By inserting shell commands in submitted querystrings, an attacker can cause the script to open and parse commands in an external file on the target system.
By supplying a long path (containing '/../' sequences) an attacker can force the script to open a file from arbitrary locations on the filesystem. Commands in this file will be executed with the privilege level of the webserver - usually 'nobody'.
Exploit / POC
DCForum 'AZ' Field Remote Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DCForum 'AZ' Field Remote Command Execution Vulnerability
Solution:
Excerpted from Baba <[email protected]>:
---
Apparently the DCForum bug was discovered in an internal security audit, and patches were sent out to all licensed users on 30-31 March 2001 ... .
The patch is available from: http://www.dcscripts.com/FAQ/sec_2001_03_31.html
--
Solution:
Excerpted from Baba <[email protected]>:
---
Apparently the DCForum bug was discovered in an internal security audit, and patches were sent out to all licensed users on 30-31 March 2001 ... .
The patch is available from: http://www.dcscripts.com/FAQ/sec_2001_03_31.html
--