Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
BID:7043
Info
Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
| Bugtraq ID: | 7043 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2003 12:00AM |
| Updated: | Mar 07 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Aleksey Sintsov <[email protected]>. |
| Vulnerable: |
Wordit Logbook 098b3 |
| Not Vulnerable: | |
Discussion
Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
A remote command execution vulnerability has been discovered in the Wordit Logbook application. This issue occurs due to insufficient sanitization of externally supplied data to the 'logbook.pl' script.
A remote attacker may exploit this condition to gain local, interactive access to the underlying host.
This vulnerability was reported to affect Wordit Logbook version 098b3 previous versions may also be affected.
A remote command execution vulnerability has been discovered in the Wordit Logbook application. This issue occurs due to insufficient sanitization of externally supplied data to the 'logbook.pl' script.
A remote attacker may exploit this condition to gain local, interactive access to the underlying host.
This vulnerability was reported to affect Wordit Logbook version 098b3 previous versions may also be affected.
Exploit / POC
Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
The following proof of concept was provided:
www.example.com/logbook.pl?file=../../../../../../../bin/cat%20logbook.pl%00|
The following proof of concept was provided:
www.example.com/logbook.pl?file=../../../../../../../bin/cat%20logbook.pl%00|
Solution / Fix
Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Wordit Logbook Logbook.pl Remote Command Execution Vulnerability
References:
References:
- Logbook Homepage (Wordit)
- Wordit Logbook Version 0.98b3 (Aleksey Sintsov
)