Mojolicious Command Line Parameter Injection Vulnerability
BID:70706
Info
Mojolicious Command Line Parameter Injection Vulnerability
| Bugtraq ID: | 70706 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2014 12:00AM |
| Updated: | Apr 13 2015 08:24PM |
| Credit: | Keine Angabe |
| Vulnerable: |
Mojolicious Mojolicious 1.16 Mojolicious Mojolicious 1.15 Mojolicious Mojolicious 1.12 Mojolicious Mojolicious 1.11 Mojolicious Mojolicious 1.10 Mojolicious Mojolicious 1.09 Mojolicious Mojolicious 0.999928 Mojolicious Mojolicious 0.999927 Mojolicious Mojolicious 0.999926 Mojolicious Mojolicious 0.991250 Mojolicious Mojolicious 0.991246 Mojolicious Mojolicious 0.991245 Mojolicious Mojolcious 1.12 |
| Not Vulnerable: | |
Discussion
Mojolicious Command Line Parameter Injection Vulnerability
Mojolicious is prone to a vulnerability that lets attackers inject command-line parameters. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to execute commands with the privileges of a user running the application. Attackers may also be able to leverage this issue to execute arbitrary code with the privileges of the user running the vulnerable application.
Mojolicious is prone to a vulnerability that lets attackers inject command-line parameters. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to execute commands with the privileges of a user running the application. Attackers may also be able to leverage this issue to execute arbitrary code with the privileges of the user running the vulnerable application.
Exploit / POC
Mojolicious Command Line Parameter Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mojolicious Command Line Parameter Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva perl-Mojolicious-5.490.0-1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Mojolicious Command Line Parameter Injection Vulnerability
References:
References:
- Mojolicious Home Page (mojolicio)
- Pro-Linux Advisory (Pro-Linux)