SuSE-SA:2001:027Vendor advisory
http://www.novell.com/linux/security/advisories/2001_027_sdb_txt.html CVE-2001-1130
SuSE 6.3/6.4/7.0 sdb - Arbitrary Command Execution
Record summary
CVE-2001-1130 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSuSE 6.3/6.4/7.0 sdb - Arbitrary Command ExecutionExploitDB exploitby Maurycy ProdeusNot analyzed1 file
References
420010802 suse: sdbsearch.cgi vulnerabilitymailing list
http://www.securityfocus.com/archive/1/201216 sdbsearch-cgi-command-execution(7003)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7003 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1130