BSCW Remote Command Execution Vulnerability
BID:3776
Info
BSCW Remote Command Execution Vulnerability
| Bugtraq ID: | 3776 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2002 12:00AM |
| Updated: | Jan 03 2002 12:00AM |
| Credit: | This vulnerability was submitted in a January 3rd, 2001 BugTraq posting by Thomas Seliger <[email protected]>. |
| Vulnerable: |
BSCW BSCW 4.0 BSCW BSCW 3.4 |
| Not Vulnerable: |
BSCW BSCW 4.0 .6 |
Discussion
BSCW Remote Command Execution Vulnerability
BSCW (Basic Support for Cooperative Work) is a web-based groupware application, allowing users to share a workspace via a web interface. It runs on Microsoft Windows NT/2000 systems, as well as a number of Linux and Unix variants.
BSCW provides functionality for calling external programs to perform conversions from one file format to another file format, such as from GIF to JPEG.
However, BSCW does not filter some shell metacharacters(such as '&',';', and '^') from requests to external file conversion programs. This makes it possible for an attacker to execute arbitrary commands on the host, with the privileges of the user running BSCW. This may allow the attacker to gain local, interactive access to the host.
BSCW (Basic Support for Cooperative Work) is a web-based groupware application, allowing users to share a workspace via a web interface. It runs on Microsoft Windows NT/2000 systems, as well as a number of Linux and Unix variants.
BSCW provides functionality for calling external programs to perform conversions from one file format to another file format, such as from GIF to JPEG.
However, BSCW does not filter some shell metacharacters(such as '&',';', and '^') from requests to external file conversion programs. This makes it possible for an attacker to execute arbitrary commands on the host, with the privileges of the user running BSCW. This may allow the attacker to gain local, interactive access to the host.
Exploit / POC
BSCW Remote Command Execution Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
BSCW Remote Command Execution Vulnerability
Solution:
The vendor has addressed this issue in version 4.0.6. Users are advised to upgrade.
BSCW BSCW 3.4
BSCW BSCW 4.0
Solution:
The vendor has addressed this issue in version 4.0.6. Users are advised to upgrade.
BSCW BSCW 3.4
-
BSCW BSCW 4.0.6
http://bscw.gmd.de/Download.html
BSCW BSCW 4.0
-
BSCW BSCW 4.0.6
http://bscw.gmd.de/Download.html