WebWho+ Remote Command Execution Vulnerability
BID:892
Info
WebWho+ Remote Command Execution Vulnerability
| Bugtraq ID: | 892 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 26 1999 12:00AM |
| Updated: | Dec 26 1999 12:00AM |
| Credit: | First posted to Bugtraq by Cody T. - hhp <[email protected]> on Dec 26, 1999. |
| Vulnerable: |
Tony Greenwood WebWho+ 1.1 |
| Not Vulnerable: | |
Discussion
WebWho+ Remote Command Execution Vulnerability
WebWho+ is a free cgi script written by Tony Greenwood for executing whois queries via the www. Though it does perform checks for shell escape characters on some parameters, it misses the 'type' variable and allows for malicious input to be sent to a shell. It is possible to execute arbitrary commands on a webserver running WebWho+ v1.1 with the uid of the webserver (usually nobody).
WebWho+ is a free cgi script written by Tony Greenwood for executing whois queries via the www. Though it does perform checks for shell escape characters on some parameters, it misses the 'type' variable and allows for malicious input to be sent to a shell. It is possible to execute arbitrary commands on a webserver running WebWho+ v1.1 with the uid of the webserver (usually nobody).
Exploit / POC
WebWho+ Remote Command Execution Vulnerability
An exploit has been made available.
An exploit has been made available.
Solution / Fix
WebWho+ Remote Command Execution Vulnerability
Solution:
The latest version of WebWho+ is not vulnerable in this manner and can be downloaded from the WebWho+ website at:
http://www.webwho.co.uk
Solution:
The latest version of WebWho+ is not vulnerable in this manner and can be downloaded from the WebWho+ website at:
http://www.webwho.co.uk