PHPNetToolpack Insecure Search Path Vulnerability
BID:4304
Info
PHPNetToolpack Insecure Search Path Vulnerability
| Bugtraq ID: | 4304 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0470 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 18 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to ppp-design <[email protected]>. |
| Vulnerable: |
PHPNetToolpack PHPNetToolpack 0.1 |
| Not Vulnerable: | |
Discussion
PHPNetToolpack Insecure Search Path Vulnerability
PHPNetToolpack provides a web interface for finger, whois and traceroute. It is written in PHP and will run on most Unix and Linux variants.
PHPNetToolpack does not use an absolute path when searching for the traceroute program. As a result, a local attacker may be able to trick PHPNetToolpack to execute arbitrary attacker-supplied code with the privileges of the webserver.
PHPNetToolpack provides a web interface for finger, whois and traceroute. It is written in PHP and will run on most Unix and Linux variants.
PHPNetToolpack does not use an absolute path when searching for the traceroute program. As a result, a local attacker may be able to trick PHPNetToolpack to execute arbitrary attacker-supplied code with the privileges of the webserver.
Solution / Fix
PHPNetToolpack Insecure Search Path Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.