OmniPCX Office Remote Command Execution Vulnerability
BID:28758
Info
OmniPCX Office Remote Command Execution Vulnerability
| Bugtraq ID: | 28758 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1331 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2008 12:00AM |
| Updated: | May 21 2008 10:04PM |
| Credit: | Digital Security |
| Vulnerable: |
Alcatel-Lucent OmniPCX Office 610 Alcatel-Lucent OmniPCX Office 510 Alcatel-Lucent OmniPCX Office 410 Alcatel-Lucent OmniPCX Office 310 Alcatel-Lucent OmniPCX Office 210 |
| Not Vulnerable: |
Alcatel-Lucent OmniPCX Office 610/014.001 Alcatel-Lucent OmniPCX Office 510/037.001 Alcatel-Lucent OmniPCX Office 410/057.001 Alcatel-Lucent OmniPCX Office 310/056.001 Alcatel-Lucent OmniPCX Office 210/091.001 |
Discussion
OmniPCX Office Remote Command Execution Vulnerability
OmniPCX Office with Internet Access services is prone to a vulnerability that lets remote attackers execute arbitrary commands because it fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands and potentially compromise the affected server.
The issue affects versions since OmniPCX Office 210/061.1.
NOTE: This BID was previously titled 'OmniPCX Office Unspecified Information Disclosure Vulnerability', but has been changed to better reflect the issue.
OmniPCX Office with Internet Access services is prone to a vulnerability that lets remote attackers execute arbitrary commands because it fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary commands and potentially compromise the affected server.
The issue affects versions since OmniPCX Office 210/061.1.
NOTE: This BID was previously titled 'OmniPCX Office Unspecified Information Disclosure Vulnerability', but has been changed to better reflect the issue.
Exploit / POC
OmniPCX Office Remote Command Execution Vulnerability
Attackers would likely use readily available tools to exploit this issue.
The following example URI is available:
http://www.example.com/cgi-data/FastJSData.cgi?id1=sh2kerr&id2=91|cat%20/etc/passwd
Attackers would likely use readily available tools to exploit this issue.
The following example URI is available:
http://www.example.com/cgi-data/FastJSData.cgi?id1=sh2kerr&id2=91|cat%20/etc/passwd
Solution / Fix
OmniPCX Office Remote Command Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the referenced advisory for more information.
Solution:
The vendor has released an advisory and fixes. Please see the referenced advisory for more information.
References
OmniPCX Office Remote Command Execution Vulnerability
References:
References:
- Alcatel-Lucent Homepage (Alcatel-Lucent)
- Alcatel-Lucent OmniPCX Office (Alcatel-Lucent)
- [DSECRG-08-020] Alcatel OmniPCX Office Remote Comand Execution (Digital Security Research Group
) - Remote Execution Vulnerability in OmniPCX Office (Alcatel-Lucent)