Glimpse HTTP aglimpse remote execution vulnerability

Risk Level: High risk vulnerability  High

Check or Attack Name: Aglimpse

Platforms: Glimpse: 2.0, Common Gateway Interface (CGI)
Description:

The aglimpse CGI script shipped with Glimpse HTTP 2.0 and WebGlimpse versions prior to 1.5 contains a vulnerability that would allow an attacker to remotely execute commands on a web server with the UID of the user running the httpd process.

Remedy:

Disable access to the aglimpse CGI script until you can upgrade to the latest version of WebGlimpse.

References:

GLIMPSE: A tool to search entire file systems, GlimpseHTTP security, http://donkey.cs.arizona.edu/security.html

CERT Vendor-Initiated Bulletin VB-97.13, Vulnerability in GlimpseHTTP and WebGlimpse CGI scripts, http://www.cert.org/ftp/cert_bulletins/VB-97.13.GlimpseHTTP.WebGlimpse


X-Force Logo
Know Your Risks