Nessus Plugin #10383
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
bizdb1-search.cgi located
- Family:
- CGI abuses
- Category:
- infos
- Copyright:
- This script is Copyright (C) 2000 Roelof Temmingh <roelof@sensepost.com>
- Summary:
- Determines the presence of cgi-bin/bizdb1-search.cgi
- Version:
- $Revision: 1.18 $
- Cve_id:
- CVE-2000-0287
- Bugtraq_id:
- 1104
- Xrefs:
- -
- Description:
BizDB is a web database integration product
using Perl CGI scripts. One of the scripts,
bizdb-search.cgi, passes a variable's
contents to an unchecked open() call and
can therefore be made to execute commands
at the privilege level of the webserver.
The variable is dbname, and if passed a
semicolon followed by shell commands they
will be executed. This cannot be exploited
from a browser, as the software checks for
a referrer field in the HTTP request. A
valid referrer field can however be created
and sent programmatically or via a network
utility like netcat.
see also : http://www.hack.co.za/daem0n/cgi/cgi/bizdb.htm
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.