CCBill WhereAmI.CGI Remote Arbitrary Command Execution Vulnerability
BID:8095
Info
CCBill WhereAmI.CGI Remote Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 8095 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2003 12:00AM |
| Updated: | Jul 03 2003 12:00AM |
| Credit: | Discovery credited to Dayne Jordan. |
| Vulnerable: |
CCBill whereami.cgi |
| Not Vulnerable: | |
Discussion
CCBill WhereAmI.CGI Remote Arbitrary Command Execution Vulnerability
It has been reported that whereami.cgi distributed by CCBill does not properly handle some types of input. Because of this, an attacker may be able to gain access to a system with the privileges of the web server process.
It has been reported that whereami.cgi distributed by CCBill does not properly handle some types of input. Because of this, an attacker may be able to gain access to a system with the privileges of the web server process.
Exploit / POC
CCBill WhereAmI.CGI Remote Arbitrary Command Execution Vulnerability
The following proof of concept has been made available by Dayne Jordan:
http://www.example.com/ccbill/whereami.cgi?g=ls
The following proof of concept has been made available by Dayne Jordan:
http://www.example.com/ccbill/whereami.cgi?g=ls
Solution / Fix
CCBill WhereAmI.CGI Remote Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.