nph-publish CGI script could allow remote file writing

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: CGI nphpublish

Platforms: Common Gateway Interface (CGI)
Description:

A vulnerability in the nph-publish script version 1.0 through 1.1 could allow remote attackers to write to files that would normally not be accessible. Under certain circumstances, this hole could be used to gain access to the vulnerable machine.

Remedy:

Remove the vulnerable version of nph-publish from your CGI-BIN directory and upgrade to at least version 1.2, which fixes this problem.

References:

Lincoln D. Stein, nph-publish script, http://stein.cshl.org/~lstein/server_publish/nph-publish.txt


X-Force Logo
Know Your Risks