Simple WAIS Interface Arbitrary Command Execution Vulnerability
BID:5127
Info
Simple WAIS Interface Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 5127 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2002 12:00AM |
| Updated: | Jun 29 2002 12:00AM |
| Credit: | Vulnerability discovery credited to John Thornton <[email protected]>. |
| Vulnerable: |
Simple WAIS Simple WAIS 1.11 |
| Not Vulnerable: | |
Discussion
Simple WAIS Interface Arbitrary Command Execution Vulnerability
The Simple WAIS interface is an integrated interface to the WAIS system. It is designed for use on Unix and Linux operating systems.
The Simple WAIS interface does not properly handle some types of input. Because of the insufficient santizing of user-supplied input, it is possible for a user with access to the interface to execute arbitrary commands with the privileges of the SWAIS daemon. This may be done by appending a command with the search, seperated by a pipe.
The Simple WAIS interface is an integrated interface to the WAIS system. It is designed for use on Unix and Linux operating systems.
The Simple WAIS interface does not properly handle some types of input. Because of the insufficient santizing of user-supplied input, it is possible for a user with access to the interface to execute arbitrary commands with the privileges of the SWAIS daemon. This may be done by appending a command with the search, seperated by a pipe.
Exploit / POC
Simple WAIS Interface Arbitrary Command Execution Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Simple WAIS Interface Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Simple WAIS Interface Arbitrary Command Execution Vulnerability
References:
References: