Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
BID:29550
Info
Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
| Bugtraq ID: | 29550 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2405 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2008 12:00AM |
| Updated: | Jun 04 2008 12:00AM |
| Credit: | Joshua J. Drake of iDefense, and an anonymous researcher discovered these issues. |
| Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.2 Sun Java System Active Server Pages (ASP) Server 4.0.1 Sun Java System Active Server Pages (ASP) Server 4.0 |
| Not Vulnerable: |
Sun Java System Active Server Pages (ASP) Server 4.0.3 |
Discussion
Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
Sun Java ASP Server is prone to multiple remote command-injection vulnerabilities because it fails to adequately sanitize user-supplied input data.
Attackers can exploit these issues to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the complete remote compromise of affected computers because the application runs with superuser privileges.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Sun Java ASP Server is prone to multiple remote command-injection vulnerabilities because it fails to adequately sanitize user-supplied input data.
Attackers can exploit these issues to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the complete remote compromise of affected computers because the application runs with superuser privileges.
Versions prior to Sun Java ASP Server 4.0.3 are vulnerable.
Exploit / POC
Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
To exploit these issues, attackers may use a browser or readily available network utilities.
To exploit these issues, attackers may use a browser or readily available network utilities.
Solution / Fix
Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Sun Java System Active Server Pages (ASP) Server 4.0
Sun Java System Active Server Pages (ASP) Server 4.0.1
Sun Java System Active Server Pages (ASP) Server 4.0.2
Solution:
The vendor has released an update. Please see the references for more information.
Sun Java System Active Server Pages (ASP) Server 4.0
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
Sun Java System Active Server Pages (ASP) Server 4.0.1
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
Sun Java System Active Server Pages (ASP) Server 4.0.2
-
Sun Sun Java System Active Server Pages 4.0.3
https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_ US/-/USD/ViewProductDetail-Start?ProductRef=SJASP-4.0.3-OTH-G-TP@CDS-C DS_SMI
References
Sun Java ASP Server Remote Arbitrary Shell Command Injection Vulnerabilities
References:
References:
- Java System Active Server Pages Homepage (Sun)
- iDefense Security Advisory 06.03.08: Sun Java System Active Server Pages Multipl (iDefense Labs
) - Multiple Security Vulnerabilities in Sun Java ASP Server may lead to execution o (Sun)
- Sun Java System Active Server Pages Multiple Command Injection Vulnerabilities (iDefense Labs)