Guestbook could allow execution of commands from remote

Risk Level: High risk vulnerability  High

Check or Attack Name: GuestBookCheck

Platforms: Common Gateway Interface (CGI)
Description:

The guestbook CGI program contains a vulnerability that allows a remote attacker to execute arbitrary commands on a web server. This is present in Selena Sol's guestbook on servers with Server Side Includes enabled.

Remedy:

Modify the guestbook.setup file, adding the word exec to the comma delimited @bad_words variable.

—OR—

Modify the guestbook.setup file so that the @allow_html variable is set to no.

References:

CERT Vendor-Initiated Bulletin VB-97.02, Security Hole in Guestbook Script for Web Servers Using SSI, http://www.cert.org/ftp/cert_bulletins/VB-97.02.sol_guestbook


X-Force Logo
Know Your Risks