Short Name |
HTTP:PKG:CARELLO-VBEXEC |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
Carello 1.3 Remote File Execution |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in Carello Shopping Cart. Version 1.3 and prior are vulnerable. To pass data between scripts during a session, the Web server uses insecure hidden form fields to specify local executables. Attackers can specify an external executable to compromise the system.
A vulnerability exists in Carello which could enable a remote user to execute arbitrary commands on the vulnerable system. Reportedly, the flaw exists in the way Carello.dll accepts HTTP requests. The Carello.dll library doesn't ensure proper checking of user supplied input for HTTP requests containing directory traversal sequences.