Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
BID:7911
Info
Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
| Bugtraq ID: | 7911 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to badpack3t <[email protected]>. |
| Vulnerable: |
The Infinity Project Infinity CGI Exploit Scanner 3.11 Beta Exploit Labs Wood's InfinityScan EZ 3.69 |
| Not Vulnerable: | |
Discussion
Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
A vulnerability in Infinity CGI Exploit Scanner may allow an attacker to bypass established host scanning policies.
Infinity CGI Exploit Scanner allows administrators to restrict specific web sites from being scanned. However, due to an input validation error in the pattern matching of hostnames, a normally restricted site, containing a wildcard DNS "A" record, may still be scanned. This will effectively bypass the established host scanning policy and scan the forbidden site.
A vulnerability in Infinity CGI Exploit Scanner may allow an attacker to bypass established host scanning policies.
Infinity CGI Exploit Scanner allows administrators to restrict specific web sites from being scanned. However, due to an input validation error in the pattern matching of hostnames, a normally restricted site, containing a wildcard DNS "A" record, may still be scanned. This will effectively bypass the established host scanning policy and scan the forbidden site.
Exploit / POC
Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Infinity CGI Exploit Scanner Host Scanning Policy Bypass Vulnerability
References:
References:
- Exploit Labs Homepage (Exploit Labs)