Verlihub Trigger Remote Command Execution Vulnerability
BID:32420
Info
Verlihub Trigger Remote Command Execution Vulnerability
| Bugtraq ID: | 32420 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5705 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2008 12:00AM |
| Updated: | Dec 30 2008 10:52PM |
| Credit: | v4lkyrius |
| Vulnerable: |
Verlihub Project Verlihub 0.9.8d RC2 |
| Not Vulnerable: | |
Discussion
Verlihub Trigger Remote Command Execution Vulnerability
Verlihub is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
Verlihub 0.9.8d RC2 is vulnerable; other versions may also be affected.
Verlihub is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
Verlihub 0.9.8d RC2 is vulnerable; other versions may also be affected.
Exploit / POC
Verlihub Trigger Remote Command Execution Vulnerability
An attacker may exploit this issue using common networking tools.
The following example command is available:
+<trigger> `cat /etc/passwd`
where <trigger> is the name of the trigger.
An attacker may exploit this issue using common networking tools.
The following example command is available:
+<trigger> `cat /etc/passwd`
where <trigger> is the name of the trigger.
Solution / Fix
Verlihub Trigger Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Verlihub Trigger Remote Command Execution Vulnerability
References:
References:
- Remote command execution and the possibility of attack with the help of symlinks (Giuseppe Iuculano)
- Verlihub Homepage (Verlihub Project)