BitMover BitKeeper Daemon Mode Remote Command Execution Vulnerability
BID:6588
Info
BitMover BitKeeper Daemon Mode Remote Command Execution Vulnerability
| Bugtraq ID: | 6588 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2003 12:00AM |
| Updated: | Jan 11 2003 12:00AM |
| Credit: | Vulnerability discovery credited to Maurycy Prodeus <[email protected]>. |
| Vulnerable: |
BitMover BitKeeper 3.0 |
| Not Vulnerable: | |
Discussion
BitMover BitKeeper Daemon Mode Remote Command Execution Vulnerability
It has been reported that BitKeeper is vulnerable to an input validation bug. When the software is run in daemon mode, it starts a service with an interface that can be connected to via HTTP. By sending specially crafted input to the service, it is possible to execute abitrary commands.
It has been reported that BitKeeper is vulnerable to an input validation bug. When the software is run in daemon mode, it starts a service with an interface that can be connected to via HTTP. By sending specially crafted input to the service, it is possible to execute abitrary commands.
References
BitMover BitKeeper Daemon Mode Remote Command Execution Vulnerability
References:
References:
- BK/Pro Product Page (BitMover)
- BitKeeper remote shell command execution/local vulnerability (Maurycy Prodeus
)