SCO Unixware "/search97cgi/vtopic" Vulnerability

Certain versions of SCO Unixware ship with a web enabled help system which is installed by default. This system, httpd-scohelphttp, ships with a faulty CGI program which will allow remote users to view files which are viewable to the account under which the web server is run as (typically 'nobody').

The problem in specific is in the following CGI:

/usr/ns-home/httpd-scohelphttp/search97cgi/vtopic

This CGI makes use of a parameter called ViewTemplate that points to an HTML Template for use with search results:

http://unixware7box:457/search97cgi/vtopic?action=view&ViewTemplate=

However, the CGI does not place any restrictions on the relative path and a user may supply their own and thereby move outside the web root directory by walking down the directory structure (../) .


 

Privacy Statement
Copyright 2010, SecurityFocus