Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Viralator CGI Input Validation Remote Shell Command Vulnerability

Viralator is a Perl CGI script designed to work with the Squid proxy server. It works in conjunction with a virus scanning engine to scan all files downloaded through the proxy server.

Viralator passes a filename taken from the URL to two shell commands used to receive the file and to scan it. It does not validate or check this input, allowing a maliciously constructed URL to contain escaped shell commands. These commands will then be executed by the Viralator script.







 

Privacy Statement
Copyright 2007, SecurityFocus