Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Open Conference Systems = 2.8.2 Remote File Inclusion

  AdMentor (banners) admin SQL injection

  local Calendar System v1.1 (lcStdLib.
inc) Remote File Include

  FdScript <= v1.3.2 Remote File Disclosure Vulnerability

From:Chris Travers <chris_(at)_metatrontech.com>
Date:28.01.2007
Subject:Full Disclosure: Arbitrary Code Execution in LedgerSMB CVE-2006-5872

CVE-2006-5872 (filed against SQL-Ledger) also affects LedgerSMB.  This
was first fixed in LedgerSMB 1.1.5 but due to a number of unrelated
bugs, we recommend upgrading to 1.1.7.  SQL-Ledger fixed the problem in
2.6.21.

This occurs due to the improper handling of input handling in the
redirect function which also allows the user to specify a file with
arguments to be run via Perl.  However, since one can specify -e as the
script (making the command line perl -e ....) one can specify whatever
code to execute one would like.

The following link demonstrates the vulnerability.

http://127.0.0.1/sql-ledger/login.pl?login=demo&script=-e%3fprint%20S
TDERR%20%27hello%20world%27%3b&action=logout

<http://127.0.0.1/sql-ledger/login.pl?login=demo&script=-e%3fprint%
20STDERR%20%27hello%20world%27%3b&action=logout
>

Best Wishes,
Chris Travers
Metatron Technology Consulting

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server