Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
BID:5111
Info
Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
| Bugtraq ID: | 5111 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2002 12:00AM |
| Updated: | Jun 26 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Microsoft Commerce Server 2000 SP2 Microsoft Commerce Server 2000 SP1 Microsoft Commerce Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
Microsoft Commerce Server is a web server product for building, deploying, and analyzing e-commerce sites. A remote command execution vulnerability has been reported in some versions of Commerce Server 2000.
The Office Web Component (OWC) package installer will accept an optional command as input. In the event that the attacker has a valid account on the server, including log on credentials, it is possible to cause an arbitrary command to be executed. The supplied command will execute with the privileges of the attacker's account.
Microsoft Commerce Server is a web server product for building, deploying, and analyzing e-commerce sites. A remote command execution vulnerability has been reported in some versions of Commerce Server 2000.
The Office Web Component (OWC) package installer will accept an optional command as input. In the event that the attacker has a valid account on the server, including log on credentials, it is possible to cause an arbitrary command to be executed. The supplied command will execute with the privileges of the attacker's account.
Exploit / POC
Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-033 (Microsoft)
- Technet Security (Microsoft)