ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
BID:55674
Info
ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 55674 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2012 12:00AM |
| Updated: | Mar 19 2015 08:33AM |
| Credit: | Gjoko Krstic |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
ViArt Shop Enterprise is prone to a remote arbitrary command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application.
ViArt Shop Enterprise 4.0.5, 4.0.8 and 4.1 are vulnerable.
ViArt Shop Enterprise is prone to a remote arbitrary command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application.
ViArt Shop Enterprise 4.0.5, 4.0.8 and 4.1 are vulnerable.
Exploit / POC
ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Attackers can use a browser to exploit this issue.
The following exploit code is available:
Solution / Fix
ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
ViArt Shop Enterprise 'sips_response.php' Remote Arbitrary Command Execution Vulnerability
References:
References:
- ViArt Shop HomePage (ViArt)
- ZSL-2012-5109 ViArt Shop Enterprise 4.1 Arbitrary Command Execution Vulnerabilit (Zero Science Lab)