68
ShopCartCGI arbitrary file reading
HTTP
2004/02/21
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Added the needed pattern_exists command to let it work properly. Corrected the plugin structure and added the accuracy values in 1.4. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send /gotopage.cgi?4242+../../../../../../../../../../../../../etc/passwd\n\n|sleep|close|pattern_exists HTTP/#.# ### *root:*
99
The HTTP request is copied from the Nessus plugin.
ShopCartCGI
The latest version of ShopCartCGI
Configuration
The remote host is running ShopCartCGI - a set of CGIs designed to set up an on-line shopping cart.There is a bug in this software which may allow an attacker to read arbitary files on the remote web server with the privileges of the web user.
The web server should be deactivated or de-installed if not necessary. If this is not possible, upgrade to the latest version of this set of CGI or disable this software.
15 minutes
Yes
http://www.securityfocus.com/bid/9670/exploit/
Yes
Yes
High
4
9
7
7
Serious
Nessus is able to check this vulnerability.
9670
12064
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch