NetCode NC Book Book.CGI Arbitrary Command Execution Vulnerability
BID:3178
Info
NetCode NC Book Book.CGI Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3178 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1114 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was announced to Bugtraq in a PoizonB0x Security Advisory on August 13, 2001. |
| Vulnerable: |
NetCode NC Book 0.2 b |
| Not Vulnerable: | |
Discussion
NetCode NC Book Book.CGI Arbitrary Command Execution Vulnerability
NetCode NC Book is a guestbook for websites distributed by NetCode.
A problem with the guestbook package can allow remote users to execute arbitrary commands. The problem is in the handling of URLs. By encapsulating commands in pipes (||), it is possible to execute commands as the web user on a local system.
This makes it possible for a remote user to gain local access with the privileges of the HTTPd process.
NetCode NC Book is a guestbook for websites distributed by NetCode.
A problem with the guestbook package can allow remote users to execute arbitrary commands. The problem is in the handling of URLs. By encapsulating commands in pipes (||), it is possible to execute commands as the web user on a local system.
This makes it possible for a remote user to gain local access with the privileges of the HTTPd process.
Solution / Fix
NetCode NC Book Book.CGI Arbitrary Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.