Networking_Utils Remote Command Execution Vulnerability
BID:6107
Info
Networking_Utils Remote Command Execution Vulnerability
| Bugtraq ID: | 6107 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2002 12:00AM |
| Updated: | Nov 05 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Tacettin Karadeniz <[email protected]>. |
| Vulnerable: |
Sourcecraft Networking_Utils 1.0 |
| Not Vulnerable: | |
Discussion
Networking_Utils Remote Command Execution Vulnerability
Networking_Utils is prone to a remote command execution vulnerability.
The issue exists in the implementation of the ping command. Shell metacharacters are not sufficiently sanitized from the domain name or IP address fields. This input will be passed directly through the shell. An attacker may exploit this issue to execute arbitrary commands with the privileges of the webserver.
Implementations of the other commands may also be affected by this vulnerability.
Networking_Utils is prone to a remote command execution vulnerability.
The issue exists in the implementation of the ping command. Shell metacharacters are not sufficiently sanitized from the domain name or IP address fields. This input will be passed directly through the shell. An attacker may exploit this issue to execute arbitrary commands with the privileges of the webserver.
Implementations of the other commands may also be affected by this vulnerability.
Exploit / POC
Networking_Utils Remote Command Execution Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Networking_Utils Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Networking_Utils Remote Command Execution Vulnerability
References:
References:
- Sourcecraft Downloads Page (Sourcecraft)
- networking_utils.php (Tacettin Karadeniz
)