AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
BID:3985
Info
AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 3985 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2002 12:00AM |
| Updated: | Jan 29 2002 12:00AM |
| Credit: | This vulnerability was originally discovered by Aleksey Sintsov <[email protected]>. |
| Vulnerable: |
AHG HTMLsearch 1.0 |
| Not Vulnerable: | |
Discussion
AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
Search.CGI is a component of the HTMLsearch Search Engine software distributed by AHG. The software is available for the Unix, Linux, and Microsoft platforms.
The search.cgi script included with the AHG Search Engine does not adequately filter input. Due to lack of sufficient input sanitization, it is possible for a remote user to pass semi-colon (;) and pipe (|) characters through a search request. This can result in the commands encapsulated between the symbols being executed with the privileges of the web server.
Search.CGI is a component of the HTMLsearch Search Engine software distributed by AHG. The software is available for the Unix, Linux, and Microsoft platforms.
The search.cgi script included with the AHG Search Engine does not adequately filter input. Due to lack of sufficient input sanitization, it is possible for a remote user to pass semi-colon (;) and pipe (|) characters through a search request. This can result in the commands encapsulated between the symbols being executed with the privileges of the web server.
Exploit / POC
AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
This problem may be exploited with a web browser.
http://www.example.com/cgi-bin/publisher/search.cgi?dir=jobs&template=;ls|&output_number=10
This problem may be exploited with a web browser.
http://www.example.com/cgi-bin/publisher/search.cgi?dir=jobs&template=;ls|&output_number=10
Solution / Fix
AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AHG Search Engine Search.CGI Arbitrary Command Execution Vulnerability
References:
References:
- Bug in AHG Search Engines Leads to Code Execution (SecuriTeam)
- Search Engines (AHG)