WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
BID:3678
Info
WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3678 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2001 12:00AM |
| Updated: | Dec 12 2001 12:00AM |
| Credit: | This vulnerability was announced in a SourceForge news letter on December 12, 2001. |
| Vulnerable: |
WebGlimpse.org WebGlimpse 2.2 .0 WebGlimpse.org WebGlimpse 2.0 WebGlimpse.org WebGlimpse 1.7.12 WebGlimpse.org WebGlimpse 1.5 WebGlimpse.org WebGlimpse 1.0 |
| Not Vulnerable: |
WebGlimpse.org WebGlimpse 2.2.2 WebGlimpse.org WebGlimpse 2.2.1 |
Discussion
WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
WebGlimpse is a web search and index software package. It is maintained by public domain, and licensed by the University of Arizona.
WebGlimpse does not properly sanitize input. By not doing so, it is possible for a remote user to pass arbitrary commands through the web interface to the underlying system. This problem can be exploited through encapsulating arbitrary commands with backquotes (`). This could allow remote command execution with the privileges of the http server process.
WebGlimpse is a web search and index software package. It is maintained by public domain, and licensed by the University of Arizona.
WebGlimpse does not properly sanitize input. By not doing so, it is possible for a remote user to pass arbitrary commands through the web interface to the underlying system. This problem can be exploited through encapsulating arbitrary commands with backquotes (`). This could allow remote command execution with the privileges of the http server process.
Exploit / POC
WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
Solution:
Fixes available:
WebGlimpse.org WebGlimpse 1.0
WebGlimpse.org WebGlimpse 1.5
WebGlimpse.org WebGlimpse 1.7.12
WebGlimpse.org WebGlimpse 2.0
WebGlimpse.org WebGlimpse 2.2 .0
Solution:
Fixes available:
WebGlimpse.org WebGlimpse 1.0
-
Webglimpse.org Webglimpse 2.2.2
http://www.webglimpse.net/download.html
WebGlimpse.org WebGlimpse 1.5
-
Webglimpse.org Webglimpse 2.2.2
http://www.webglimpse.net/download.html
WebGlimpse.org WebGlimpse 1.7.12
-
Webglimpse.org Webglimpse 2.2.2
http://www.webglimpse.net/download.html
WebGlimpse.org WebGlimpse 2.0
-
Webglimpse.org Webglimpse 2.2.2
http://www.webglimpse.net/download.html
WebGlimpse.org WebGlimpse 2.2 .0
-
Webglimpse.org Webglimpse 2.2.2
http://www.webglimpse.net/download.html
References
WebGlimpse Character Filtering Arbitrary Command Execution Vulnerability
References:
References: