37 Virgil CGI Scanner 0.x command execution HTTP 2003/11/14 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Optimized the trigger pattern to be more accurate in version 1.3. Corrected the plugin structure and added the accuracy values in 1.4. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send GET /cgi-bin/virgil.cgi?tar=-le/bin/sh HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 * 99 This plugin was written with the ATK Attack Editor. http://www.securityfocus.com/archive/1/296635 Virgil CGI Scanner 0.x up to 0.9 Virgil CGI Scanner newer than 0.9 Configuration Virgil CGI Scanner is an open-source CGI scanner with web frontend. The software fails to sufficiently sanitize user-supplied input. By passing a malicious value to a CGI variable, it may be possible for a remote attacker to execute arbitrary system commands, with the privileges of the webserver process. Upgrade to Virgil CGI Scanner 1.0 or use htaccess authentication for the scanning service. 15 minutes Yes http://www.securityfocus.com/bid/6031/exploit/ Yes Yes High 5 7 8 7 6031 7368 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch