(Vendor Issues Fix) YaPiG Input Validation Holes Let Remote Users Execute Arbitrary Commands
|
|
SecurityTracker Alert ID: 1011759
|
|
SecurityTracker URL: http://securitytracker.com/id?1011759
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
|
OSVDB Reference: 8657
(Links to External Site)
|
Date: Oct 18 2004
|
Impact: Execution of arbitrary code via network, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 0.92b
|
Description: An input validation vulnerability was reported in YaPiG. A remote user can execute arbitrary operating system commands on the target system.
aCiDBiTS reported that 'add_comments.php' and 'functions.php' do not properly validate user-supplied input. A remote user can send
specially crafted inputs to create a file with an arbitrary file extension and containing arbitrary contents.
A remote user can
exploit these flaws to upload a PHP file and then have the web server execute the PHP code.
|
Impact: A remote user can execute arbitrary commands on the target system with the privileges of the target web service.
|
Solution: The vendor has issued a fixed version (0.92.2b), available at:
http://sourceforge.net/project/showfiles.php?group_id=93674
|
Vendor URL: yapig.sourceforge.net/ (Links to External Site)
|
Cause: Access control error, Input validation error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Mon, 18 Oct 2004 10:14:53 -0400
Subject: http://sourceforge.net/tracker/index.php?func=detail&aid=1007246&group_id=93674&atid=605076
|
> This bug was solved in 0.92.2b release.
>
> Please if you have a version previous to 0.92.2, please
> UPDATE yapig.
|
|