SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
BID:26963
Info
SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
| Bugtraq ID: | 26963 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6515 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | niekt0 is credited with the discovery of this issue. |
| Vulnerable: |
SiteScape Forum ZX 0 SiteScape Forum ST 0 |
| Not Vulnerable: | |
Discussion
SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
SiteScape Forum is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the webserver process. Successful exploits could compromise the application and possibly the underlying system.
SiteScape Forum is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands in the context of the webserver process. Successful exploits could compromise the application and possibly the underlying system.
Exploit / POC
SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/forum/support/dispatch.cgi/0;command
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/forum/support/dispatch.cgi/0;command
Solution / Fix
SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
Solution:
The vendor released a fix to address this issue. Please see the references for more information.
Solution:
The vendor released a fix to address this issue. Please see the references for more information.
References
SiteScape Forum 'dispatch.cgi' Tcl Command Injection Vulnerability
References:
References:
- Home Page (SiteScape)
- Vendor Patch (SiteScape)
- SiteScape Forum TCL injection ("lolo lolo"
)