Jason Maloney's Guestbook Remote Command Execution Vulnerability
BID:9139
Info
Jason Maloney's Guestbook Remote Command Execution Vulnerability
| Bugtraq ID: | 9139 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2003 12:00AM |
| Updated: | Dec 01 2003 12:00AM |
| Credit: | This issue was discovered by <[email protected]>. |
| Vulnerable: |
Jason Maloney Guestbook 3.0 |
| Not Vulnerable: | |
Discussion
Jason Maloney's Guestbook Remote Command Execution Vulnerability
A vulnerability has been reported in Jason Maloney's Guestbook that could result in remote command execution with the privileges of the web server. The problem occurs due to the application failing to sanitize sensitive script variables after handling POST requests. This could potentially result in the execution of arbitrary system executables.
A vulnerability has been reported in Jason Maloney's Guestbook that could result in remote command execution with the privileges of the web server. The problem occurs due to the application failing to sanitize sensitive script variables after handling POST requests. This could potentially result in the execution of arbitrary system executables.
Exploit / POC
Jason Maloney's Guestbook Remote Command Execution Vulnerability
Exploit code has been made available.
Exploit code has been made available.
Solution / Fix
Jason Maloney's Guestbook Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Jason Maloney's Guestbook Remote Command Execution Vulnerability
References:
References: