vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
BID:6038
Info
vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
| Bugtraq ID: | 6038 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2002 12:00AM |
| Updated: | Oct 24 2002 12:00AM |
| Credit: | Discovery credited to Ignacio Vazquez. |
| Vulnerable: |
vpopmail-CGIApps vpopmail-CGIApps 0.2 |
| Not Vulnerable: |
vpopmail-CGIApps vpopmail-CGIApps 0.3 |
Discussion
vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
A remote command execution vulnerability has been discovered in vpopmail-CGIApps v0.2.
Due to insufficient sanitization of user-supplied input in vpasswd.cgi, it is possible to pass malicious commands to the os.system() function.
Exploiting this issue allows a remote attacker to execute arbitrary system commands with the permissions of the web server.
A remote command execution vulnerability has been discovered in vpopmail-CGIApps v0.2.
Due to insufficient sanitization of user-supplied input in vpasswd.cgi, it is possible to pass malicious commands to the os.system() function.
Exploiting this issue allows a remote attacker to execute arbitrary system commands with the permissions of the web server.
Exploit / POC
vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
Solution:
The vendor has confirmed this issue and address it in the latest version of the software. Users are advised to upgrade to the latest release.
vpopmail-CGIApps vpopmail-CGIApps 0.2
Solution:
The vendor has confirmed this issue and address it in the latest version of the software. Users are advised to upgrade to the latest release.
vpopmail-CGIApps vpopmail-CGIApps 0.2
-
vpopmail-CGIApps vpopmail-CGIApps v0.3
http://diario.buscadoc.org/index.php?topic=Programas
References
vpopmail-CGIApps 'vpasswd.cgi' Remote Command Execution Vulnerability
References:
References: