CSGuestbook Remote Command Execution Vulnerability
BID:4448
Info
CSGuestbook Remote Command Execution Vulnerability
| Bugtraq ID: | 4448 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2002 12:00AM |
| Updated: | Apr 08 2002 12:00AM |
| Credit: | This issue was publicized by Steve Gustin <[email protected]>. |
| Vulnerable: |
CGISCRIPT.NET csGuestbook 1.0 |
| Not Vulnerable: | |
Discussion
CSGuestbook Remote Command Execution Vulnerability
csGuestbook is web guestbook software. It will run on most Unix and Linux variants.
csGuestbook is prone to an issue which may enable an attacker to execute Perl code with the privileges of the webserver process.
For exploitation to be successful, the attacker must pass properly URL encoded Perl code in CGI parameters via a web request. For example:
http://host/cgi-bin/csGuestbook.cgi?command=savesetup&setup=PERL_CODE_HERE
csGuestbook is web guestbook software. It will run on most Unix and Linux variants.
csGuestbook is prone to an issue which may enable an attacker to execute Perl code with the privileges of the webserver process.
For exploitation to be successful, the attacker must pass properly URL encoded Perl code in CGI parameters via a web request. For example:
http://host/cgi-bin/csGuestbook.cgi?command=savesetup&setup=PERL_CODE_HERE
Exploit / POC
CSGuestbook Remote Command Execution Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
CSGuestbook Remote Command Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CSGuestbook Remote Command Execution Vulnerability
References:
References:
- CGISCRIPT.NET Homepage (CGISCRIPT.NET)