Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
BID:6326
Info
Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
| Bugtraq ID: | 6326 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2002 12:00AM |
| Updated: | Dec 05 2002 12:00AM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Cobalt RaQ 4.0 |
| Not Vulnerable: | |
Discussion
Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
The RaQ4 is a server appliance distributed and maintained by Sun Microsystems.
A vulnerability has been reported in the web administration interface of the RaQ4. It is possible for a remote attacker to execute commands. By passing malicious email parameter to the vulnerable CGI script, commands are carried out in the security context of the administration server.
This vulnerability only affects RaQ4 servers with the RaQ4 Security Hardening Package (SHP) installed. The SHP is not installed by default.
The RaQ4 is a server appliance distributed and maintained by Sun Microsystems.
A vulnerability has been reported in the web administration interface of the RaQ4. It is possible for a remote attacker to execute commands. By passing malicious email parameter to the vulnerable CGI script, commands are carried out in the security context of the administration server.
This vulnerability only affects RaQ4 servers with the RaQ4 Security Hardening Package (SHP) installed. The SHP is not installed by default.
Exploit / POC
Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
Exploit contributed by <[email protected]>.
Exploit contributed by <[email protected]>.
Solution / Fix
Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
Solution:
The vendor has fixed this issue with package RaQ4-en-Security-2.0.1-SHP_REM.pkg.
Cobalt RaQ 4.0
Solution:
The vendor has fixed this issue with package RaQ4-en-Security-2.0.1-SHP_REM.pkg.
Cobalt RaQ 4.0
-
Sun RaQ4-en-Security-2.0.1-SHP_REM.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-en-Security-2.0.1 -SHP_REM.pkg
References
Cobalt RaQ4 Administrative Interface Command Execution Vulnerability
References:
References: