WWWIsis Remote Command Execution Vulnerability
BID:4383
Info
WWWIsis Remote Command Execution Vulnerability
| Bugtraq ID: | 4383 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0508 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovery of this issue is credited to Klaus Ripke <[email protected]>. |
| Vulnerable: |
WWWIsis WWWIsis 3.45 WWWIsis WWWIsis 3.3 |
| Not Vulnerable: |
WWWIsis WWWIsis 5.0 WWWIsis WWWIsis 4.0 |
Discussion
WWWIsis Remote Command Execution Vulnerability
WWWIsis provides a web interface for accessing ISIS databases. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
It is possible for a remote attacker to execute commands on the underlying shell of the host running the vulnerable software. Such commands will be executed with the privileges of the webserver process.
This issue has been reported for 3.x versions. Other versions are not affected by this vulnerability. Additionally, JavaISIS and other tools based on WWWIsis may also be affected.
WWWIsis provides a web interface for accessing ISIS databases. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
It is possible for a remote attacker to execute commands on the underlying shell of the host running the vulnerable software. Such commands will be executed with the privileges of the webserver process.
This issue has been reported for 3.x versions. Other versions are not affected by this vulnerability. Additionally, JavaISIS and other tools based on WWWIsis may also be affected.
Exploit / POC
WWWIsis Remote Command Execution Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
WWWIsis Remote Command Execution Vulnerability
Solution:
This issue is not present in versions 4.0 and later. Those affected are advised to upgrade to the most recent version.
WWWIsis WWWIsis 3.3
WWWIsis WWWIsis 3.45
Solution:
This issue is not present in versions 4.0 and later. Those affected are advised to upgrade to the most recent version.
WWWIsis WWWIsis 3.3
-
WWWIsis WWWIsis 5.0
http://www.bireme.br/wwwisis/I/download.htm
WWWIsis WWWIsis 3.45
-
WWWIsis WWWIsis 5.0
http://www.bireme.br/wwwisis/I/download.htm