Mapbender 'factor' Parameter Remote Code Injection Vulnerability
BID:28195
Info
Mapbender 'factor' Parameter Remote Code Injection Vulnerability
| Bugtraq ID: | 28195 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0300 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2008 12:00AM |
| Updated: | Mar 12 2008 06:31PM |
| Credit: | RedTeam Pentesting GmbH is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mapbender Mapbender 2.4.4 Mapbender Mapbender 2.4.3 Mapbender Mapbender 2.4.2 Mapbender Mapbender 2.4.1 Mapbender Mapbender 2.4 |
| Not Vulnerable: |
Mapbender Mapbender 2.4.5 rc1 |
Discussion
Mapbender 'factor' Parameter Remote Code Injection Vulnerability
Mapbender is prone to a remote code-injection vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows attackers to execute arbitrary code within the context of the webserver.
This issue affects Mapbender 2.4 to 2.4.4; other versions may also be affected.
Mapbender is prone to a remote code-injection vulnerability because the application fails to properly sanitize user-supplied input.
Exploiting this issue allows attackers to execute arbitrary code within the context of the webserver.
This issue affects Mapbender 2.4 to 2.4.4; other versions may also be affected.
Exploit / POC
Mapbender 'factor' Parameter Remote Code Injection Vulnerability
Attackers can exploit this issue via a browser.
The following proof of concept is available:
Attackers can exploit this issue via a browser.
The following proof of concept is available:
Solution / Fix
Mapbender 'factor' Parameter Remote Code Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Mapbender Mapbender 2.4.4
Solution:
The vendor has released updates. Please see the references for more information.
Mapbender Mapbender 2.4.4
-
Mapbender mapbender_2.4.5_rc1.zip
http://www.mapbender.org/download/mapbender_2.4.5_rc1.zip
References
Mapbender 'factor' Parameter Remote Code Injection Vulnerability
References:
References:
- Advisory: Remote Command Execution in Mapbender (RedTeam Pentesting GmbH)
- Mapbender Homepage (Mapbender)