WebC Local Configuration File Format String Vulnerability
BID:7274
Info
WebC Local Configuration File Format String Vulnerability
| Bugtraq ID: | 7274 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 03 2003 12:00AM |
| Updated: | Apr 03 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
AutomatedShops WebC 5.0 10 AutomatedShops WebC 5.0 05 AutomatedShops WebC 5.0 AutomatedShops WebC 2.0 11 |
| Not Vulnerable: |
AutomatedShops WebC 5.0 20 |
Discussion
WebC Local Configuration File Format String Vulnerability
A vulnerability has been reported in the WebC scripting language. The problem occurs when parsing data located in a user-specified configuration file. Due to a programming error when accessing the configuration file with a formatted function, it may be possible to corrupt memory.
Successful exploitation of this issue may allow an attacker to execute arbitrary commands with elevated privileges.
A vulnerability has been reported in the WebC scripting language. The problem occurs when parsing data located in a user-specified configuration file. Due to a programming error when accessing the configuration file with a formatted function, it may be possible to corrupt memory.
Successful exploitation of this issue may allow an attacker to execute arbitrary commands with elevated privileges.
Exploit / POC
WebC Local Configuration File Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WebC Local Configuration File Format String Vulnerability
Solution:
The vendor has released a new version to address this issue:
AutomatedShops WebC 2.0 11
AutomatedShops WebC 5.0 05
AutomatedShops WebC 5.0 10
AutomatedShops WebC 5.0
Solution:
The vendor has released a new version to address this issue:
AutomatedShops WebC 2.0 11
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0 05
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0 10
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
AutomatedShops WebC 5.0
-
AutomatedShops WebC 5.020
ftp://ftp.automatedshops.com/pub/webc/5.020/
References
WebC Local Configuration File Format String Vulnerability
References:
References:
- AutomatedShops Homepage (AutomatedShops)
- Multiple vulnerabilities in AutomatedShops WebC shopping cart (Carl Livitt
)