Joel Palmius Mod_Survey Input Validation Vulnerability
BID:3672
Info
Joel Palmius Mod_Survey Input Validation Vulnerability
| Bugtraq ID: | 3672 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2001 12:00AM |
| Updated: | Dec 12 2001 12:00AM |
| Credit: | Details of this vulnerability were initially released in the changelog of Mod_Survey 3.0.6 on December 7th, 2001. |
| Vulnerable: |
Joel Palmius Mod_Survey 3.0 .5 Joel Palmius Mod_Survey 3.0 .4 Joel Palmius Mod_Survey 3.0 .3 Joel Palmius Mod_Survey 3.0 .2 Joel Palmius Mod_Survey 3.0 .1 Joel Palmius Mod_Survey 3.0 .0 |
| Not Vulnerable: |
Joel Palmius Mod_Survey 3.0 .6 |
Discussion
Joel Palmius Mod_Survey Input Validation Vulnerability
Mod_Survey is a Perl module which allows web users to create online questionaires. It is written and maintained by Joel Palmius.
Mod_Survey does not adequately validate user-supplied input. A number of characters are not sanitized from text fields or HTTP requests. For example, semi-colons(;) are used to delimit fields in Mod_Survey and extraneous use of semi-colons may cause unexpected behavior to occur.
Additionally, this may make it possible for a remote attacker to execute arbitrary commands on the shell of a host, in the case of a specially crafted request which contains shell metacharacters. Though this possibility has not been confirmed.
Mod_Survey is a Perl module which allows web users to create online questionaires. It is written and maintained by Joel Palmius.
Mod_Survey does not adequately validate user-supplied input. A number of characters are not sanitized from text fields or HTTP requests. For example, semi-colons(;) are used to delimit fields in Mod_Survey and extraneous use of semi-colons may cause unexpected behavior to occur.
Additionally, this may make it possible for a remote attacker to execute arbitrary commands on the shell of a host, in the case of a specially crafted request which contains shell metacharacters. Though this possibility has not been confirmed.
Exploit / POC
Joel Palmius Mod_Survey Input Validation Vulnerability
This vulnerability can be exploited with a web browser.
This vulnerability can be exploited with a web browser.
Solution / Fix
Joel Palmius Mod_Survey Input Validation Vulnerability
Solution:
This issue has been addressed in version 3.0.6 of the affected software. Users are advised to upgrade.
Joel Palmius Mod_Survey 3.0 .4
Joel Palmius Mod_Survey 3.0 .0
Joel Palmius Mod_Survey 3.0 .2
Joel Palmius Mod_Survey 3.0 .5
Joel Palmius Mod_Survey 3.0 .3
Joel Palmius Mod_Survey 3.0 .1
Solution:
This issue has been addressed in version 3.0.6 of the affected software. Users are advised to upgrade.
Joel Palmius Mod_Survey 3.0 .4
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
Joel Palmius Mod_Survey 3.0 .0
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
Joel Palmius Mod_Survey 3.0 .2
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
Joel Palmius Mod_Survey 3.0 .5
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
Joel Palmius Mod_Survey 3.0 .3
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
Joel Palmius Mod_Survey 3.0 .1
-
Joel Palmius modsurvey-3.0.6-stable.tar.gz
http://gathering.itm.mh.se/modsurvey/modsurvey-3.0.6-stable.tar.gz
References
Joel Palmius Mod_Survey Input Validation Vulnerability
References:
References:
- Mod_Survey Homepage (Joel Palmius )