PHPPing Remote Command Execution Vulnerability
BID:7030
Info
PHPPing Remote Command Execution Vulnerability
| Bugtraq ID: | 7030 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2003 12:00AM |
| Updated: | Mar 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability is credited to [email protected]. |
| Vulnerable: |
PHPPing PHPPing 0.1 |
| Not Vulnerable: | |
Discussion
PHPPing Remote Command Execution Vulnerability
A vulnerability has been reported in PHPPing that may allow remote attackers to execute commands on vulnerable systems.
The vulnerability exists in the index.php script file. Some variables are not properly sanitized of malicious shell metacharacters. An attacker can exploit this vulnerability by executing the PHPPing script and include malicious shell metacharacters as values for various parameters.
A vulnerability has been reported in PHPPing that may allow remote attackers to execute commands on vulnerable systems.
The vulnerability exists in the index.php script file. Some variables are not properly sanitized of malicious shell metacharacters. An attacker can exploit this vulnerability by executing the PHPPing script and include malicious shell metacharacters as values for various parameters.
Exploit / POC
PHPPing Remote Command Execution Vulnerability
The following proof of concept was provided:
http://www.target.com/phpping/index.php?pingto=www.test.com%20|%20dir
The following proof of concept was provided:
http://www.target.com/phpping/index.php?pingto=www.test.com%20|%20dir
Solution / Fix
PHPPing Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPPing Remote Command Execution Vulnerability
References:
References:
- [SCSA-009] Remote Command Execution Vulnerability in PHP Ping ("Grégory" Le Bras
)