37
Virgil CGI Scanner 0.x command execution
HTTP
2003/11/14
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Optimized the trigger pattern to be more accurate in version 1.3. Corrected the plugin structure and added the accuracy values in 1.4. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET /cgi-bin/virgil.cgi?tar=-le/bin/sh HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 *
99
This plugin was written with the ATK Attack Editor.
http://www.securityfocus.com/archive/1/296635
Virgil CGI Scanner 0.x up to 0.9
Virgil CGI Scanner newer than 0.9
Configuration
Virgil CGI Scanner is an open-source CGI scanner with web frontend. The software fails to sufficiently sanitize user-supplied input. By passing a malicious value to a CGI variable, it may be possible for a remote attacker to execute arbitrary system commands, with the privileges of the webserver process.
Upgrade to Virgil CGI Scanner 1.0 or use htaccess authentication for the scanning service.
15 minutes
Yes
http://www.securityfocus.com/bid/6031/exploit/
Yes
Yes
High
5
7
8
7
6031
7368
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch