PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
BID:33525
Info
PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
| Bugtraq ID: | 33525 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2009 12:00AM |
| Updated: | Feb 02 2009 05:49PM |
| Credit: | Perforin |
| Vulnerable: |
PerlSoft PerlSoft Gästebuch 1.7b |
| Not Vulnerable: | |
Discussion
PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
PerlSoft Gästebuch is prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue occurs because the application fails to adequately sanitize user-supplied input. Note that an attacker must have administrative access to the script to exploit this issue.
Successful attacks can compromise the affected application and possibly the underlying computer.
PerlSoft Gästebuch 1.7b is vulnerable; other versions may also be affected.
PerlSoft Gästebuch is prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue occurs because the application fails to adequately sanitize user-supplied input. Note that an attacker must have administrative access to the script to exploit this issue.
Successful attacks can compromise the affected application and possibly the underlying computer.
PerlSoft Gästebuch 1.7b is vulnerable; other versions may also be affected.
Exploit / POC
PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PerlSoft Gästebuch 'admincenter.cgi' Remote Command Execution Vulnerability
References:
References:
- PerlSoft Homepage (PerlSoft)
- PerlSoft Guestbook v1.7b Bruteforcer + RCE! (Perforin
)