Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
BID:3385
Info
Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 3385 |
| Class: | Design Error |
| CVE: |
CVE-2001-1298 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was submitted to BugTraq on October 2nd, 2001 by atil <[email protected]> and genetics <[email protected]>. |
| Vulnerable: |
Grant Horwood Webodex 1.0 |
| Not Vulnerable: | |
Discussion
Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
Grant Horwood Webodex is web based mailing list management system written in PHP.
A problem exists in Webodex that will allow a remote attacker to execute arbitrary code on a host running the software(with the privileges of the webserver process). It is possible to supply arbitrary data to the $include variable. As a result, the affected script may be redirected to execute arbitrary code located on an external host, as specified by the attacker.
This issue can be exploited if the remote attacker submits a maliciously crafted URL.
Grant Horwood Webodex is web based mailing list management system written in PHP.
A problem exists in Webodex that will allow a remote attacker to execute arbitrary code on a host running the software(with the privileges of the webserver process). It is possible to supply arbitrary data to the $include variable. As a result, the affected script may be redirected to execute arbitrary code located on an external host, as specified by the attacker.
This issue can be exploited if the remote attacker submits a maliciously crafted URL.
Exploit / POC
Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Grant Horwood Webodex Remote Arbitrary Code Execution Vulnerability
References:
References:
- Webodex (Grant Horwood)