Gnatsweb Remote Command Execution Vulnerability
BID:2938
Info
Gnatsweb Remote Command Execution Vulnerability
| Bugtraq ID: | 2938 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2001 12:00AM |
| Updated: | Jun 27 2001 12:00AM |
| Credit: | Discovered by Joost Pol <[email protected]>. |
| Vulnerable: |
GNU Gnatsweb 3.95 GNATS 4 GNU Gnatsweb 2.8.1 GNU Gnatsweb 2.8 GNU Gnatsweb 2.7 beta |
| Not Vulnerable: | |
Discussion
Gnatsweb Remote Command Execution Vulnerability
Gnatsweb is a web-based interface to the GNU bug management system 'Gnats'. In recent versions of Gnatsweb, a new help system has been implemented.
This help system contains a vulnerability that can allow remote attackers to view arbitrary files on webservers running gnatsweb. The value of the 'help_file' HTML variable is passed directly to the open() perl function when a help file is being opened.
It is thus possible for remote attackers to submit requests that will cause command execution or disclosure of arbitrary webserver readable files on the host running Gnatsweb.
This vulnerability could allow an attacker to gain 'local' access to the host. It is significantly easier to compromise the entire system if local access is obtained.
Gnatsweb is a web-based interface to the GNU bug management system 'Gnats'. In recent versions of Gnatsweb, a new help system has been implemented.
This help system contains a vulnerability that can allow remote attackers to view arbitrary files on webservers running gnatsweb. The value of the 'help_file' HTML variable is passed directly to the open() perl function when a help file is being opened.
It is thus possible for remote attackers to submit requests that will cause command execution or disclosure of arbitrary webserver readable files on the host running Gnatsweb.
This vulnerability could allow an attacker to gain 'local' access to the host. It is significantly easier to compromise the entire system if local access is obtained.
Exploit / POC
Gnatsweb Remote Command Execution Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
References
Gnatsweb Remote Command Execution Vulnerability
References:
References:
- Gnats Homepage (GNU)
- Gnatsweb Security Advisory (GNU)