PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
BID:9037
Info
PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
| Bugtraq ID: | 9037 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0626 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | The disclosure of this issue has been credited to Martin O'Neal <[email protected]> of Corsaire Security. |
| Vulnerable: |
PeopleSoft PeopleTools 8.43 PeopleSoft PeopleTools 8.42 PeopleSoft PeopleTools 8.41 PeopleSoft PeopleTools 8.40 PeopleSoft PeopleTools 8.20 PeopleSoft PeopleTools 8.19 PeopleSoft PeopleTools 8.19 PeopleSoft PeopleTools 8.18 PeopleSoft PeopleTools 8.17 PeopleSoft PeopleTools 8.16 PeopleSoft PeopleTools 8.15 PeopleSoft PeopleTools 8.14 PeopleSoft PeopleTools 8.13 PeopleSoft PeopleTools 8.12 PeopleSoft PeopleTools 8.11 PeopleSoft PeopleTools 8.10 PeopleSoft PeopleTools 8.4 PeopleSoft PeopleTools 7.0 6 |
| Not Vulnerable: | |
Discussion
PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
A vulnerability has been reported to be present in the PeopleBooks component of PeopleTools that may allow a remote attacker to traverse outside the server root directory in order to gain access to sensitive information. The problem exists due to insufficient sanitization of 'headername' and 'footername' arguments of the psdoccgi.exe CGI script used by PeopleBooks.
PeopleTools versions 8.43 and prior have been reported to be prone to this vulnerability.
A vulnerability has been reported to be present in the PeopleBooks component of PeopleTools that may allow a remote attacker to traverse outside the server root directory in order to gain access to sensitive information. The problem exists due to insufficient sanitization of 'headername' and 'footername' arguments of the psdoccgi.exe CGI script used by PeopleBooks.
PeopleTools versions 8.43 and prior have been reported to be prone to this vulnerability.
Exploit / POC
PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
Solution:
PeopleSoft has released the following patches to address this issue.
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
Users are advised to obtain patches from PeopleSoft Customer Connection website.
Solution:
PeopleSoft has released the following patches to address this issue.
Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11
Users are advised to obtain patches from PeopleSoft Customer Connection website.
References
PeopleSoft PeopleBooks psdoccgi.exe Directory Traversal Vulnerability
References:
References:
- PeopleSoft Customer Connection (PeopleSoft)
- PeopleSoft Homepage (PeopleSoft)
- Corsaire Security Advisory: PeopleSoft PeopleBooks Search CGI multiple argument ("advisories"
)