Karrigell Eval注入漏洞

Karrigell Eval注入漏洞

漏洞ID 1108955 漏洞类型 设计错误
发布时间 2005-07-31 更新时间 2005-10-20
图片[1]-Karrigell Eval注入漏洞-安全小百科CVE编号 CVE-2005-2483
图片[2]-Karrigell Eval注入漏洞-安全小百科CNNVD-ID CNNVD-200508-072
漏洞平台 CGI CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/26066
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-072
|漏洞详情
Karrigell2.1.8之前的版本中存在eval注入漏洞。该漏洞使得远程攻击者可以借助于Karrigell服务(.ks)脚本的修改参数执行任意Python代码。这样便可从该脚本所使用的库中引用函数。
|漏洞EXP
source: http://www.securityfocus.com/bid/14463/info

Karrigell is susceptible to an arbitrary Python command execution vulnerability. This issue is due to a design flaw that allows remote attackers to execute Python commands that they are not intended to have access to.

Attackers may exploit this vulnerability to execute arbitrary Python commands in the context of the Web server hosting the Karrigell framework. This allows remote malicious users to cause denial of service conditions, create or overwrite arbitrary files, and likely compromise the hosting computer. 

The following examples will cause a denial of service condition:
http://www.example.com/test.ks/raw_input
http://www.example.com/test.ks/file?%22*10000000&mode=w

The following example will create a file on the local filesystem on the hosting computer:
http://www.example.com/test.ks/file?%22*2&mode=w
|参考资料

来源:MLIST
名称:[karrigell-main]20050802Re:SECURITY:pythonnamespaceexposure
链接:http://sourceforge.net/mailarchive/message.php?msg_id=12539317
来源:SECUNIA
名称:16319
链接:http://secunia.com/advisories/16319
来源:XF
名称:karrigel-dos(21668)
链接:http://xforce.iss.net/xforce/xfdb/21668
来源:BID
名称:14463
链接:http://www.securityfocus.com/bid/14463
来源:OSVDB
名称:18506
链接:http://www.osvdb.org/18506
来源:MLIST
名称:[karrigell-main]20050731SECURITY:pythonnamespaceexposure
链接:http://sourceforge.net/mailarchive/forum.php?thread_id=7863293&forum;_id=32318

相关推荐: BBGallery Image Tag HTML Injection Vulnerability

BBGallery Image Tag HTML Injection Vulnerability 漏洞ID 1101988 漏洞类型 Input Validation Error 发布时间 2002-06-11 更新时间 2002-06-11 CVE编号 N/…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享