[14150] in bugtraq

home help back first fref pref prev next nref lref last post

infosrch.cgi vulnerability (IRIX 6.5)

daemon@ATHENA.MIT.EDU (rpc)
Fri Mar 3 11:46:40 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.LNX.4.10.10003021059360.21162-100000@inetarena.com>
Date:         Thu, 2 Mar 2000 11:12:41 -0800
Reply-To: rpc <rpc@INETARENA.COM>
From: rpc <rpc@INETARENA.COM>
X-To:         bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM

Hi,

InfoSearch is a web-based interface to books, manpages, and relnotes,
distributed by SGI.

No suprises here, no parsing is done on the 'fname' variable before being
passed to man2html. (i.e. when cmd is 'getdoc' and db is 'man').

Also, fname is the _full path_ to the manpage/relnote! I'm sure there's
more vulnerabilities lurking about in this script.

Example:
http://my.really.expensive.sgi.box/cgi-bin/infosrch.cgi?cmd=getdoc&db=man&fname=|/bin/id

Thanks,
--jared <rpc@inetarena.com> || <h@ckz.org>
Security Specialist -- Internet Arena

home help back first fref pref prev next nref lref last post