Glimpse HTTP aglimpse remote execution vulnerability |
---|
Risk Level: | High | Check or Attack Name: Aglimpse |
---|---|---|
Platforms: | Glimpse: 2.0, Common Gateway Interface (CGI) | |
Description: | The aglimpse CGI script shipped with Glimpse HTTP 2.0 and WebGlimpse versions prior to 1.5 contains a vulnerability that would allow an attacker to remotely execute commands on a web server with the UID of the user running the httpd process. |
|
Remedy: | Disable access to the aglimpse CGI script until you can upgrade to the latest version of WebGlimpse. |
|
References: | GLIMPSE: A tool to search entire file systems, GlimpseHTTP security, http://donkey.cs.arizona.edu/security.html CERT Vendor-Initiated Bulletin VB-97.13, Vulnerability in GlimpseHTTP and WebGlimpse CGI scripts, http://www.cert.org/ftp/cert_bulletins/VB-97.13.GlimpseHTTP.WebGlimpse |
Know Your Risks |