HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
BID:4652
Info
HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
| Bugtraq ID: | 4652 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0610 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Vulnerability announced in an HP Security Advisory. |
| Vulnerable: |
HP MPE/iX 7.0 HP MPE/iX 6.5 HP MPE/iX 6.0 |
| Not Vulnerable: | |
Discussion
HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
MPE/iX is an Internet-ready operating system for the HP e3000 class servers.
Under some conditions, it may be possible for a user with access to an FTP server to execute commands on a MPE/iX server. Due to insufficient checking of input by FTP users, it is possible to pass arbitrary commands embedded in the argument to LIST. This could allow a user without regular shell access to the host to gain access.
MPE/iX is an Internet-ready operating system for the HP e3000 class servers.
Under some conditions, it may be possible for a user with access to an FTP server to execute commands on a MPE/iX server. Due to insufficient checking of input by FTP users, it is possible to pass arbitrary commands embedded in the argument to LIST. This could allow a user without regular shell access to the host to gain access.
Exploit / POC
HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
Solution:
Fixes available:
HP MPE/iX 6.0
HP MPE/iX 6.5
HP MPE/iX 7.0
Solution:
Fixes available:
HP MPE/iX 6.0
-
HP FTPGD91A
http://itrc.hp.com
HP MPE/iX 6.5
-
HP FTPGD92A
http://itrc.hp.com
HP MPE/iX 7.0
-
HP FTPGD93A
http://itrc.hp.com
References
HP MPE/iX FTPSRVR Arbitrary Shell Command Execution Vulnerability
References:
References: