OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]
From: Vanja Hrustic (vanjaRELAYGROUP.COM)
Date: Sat Jun 10 2000 - 06:17:12 CDT


fusysITAPAC.NET wrote:
> There are at least two distinct bugs we'll mention.

Also, buffer overflow exists in userreg.cgi, which enables remote user
to execute any command as root.

It is also possible to change the password for system users, which don't
have the password already (like 'operator', 'gopher', etc.).

And probably some more (it was pointless going any further - apps seem
to be full of holes).

3RSoft did not respond to mail (sent around 3 months ago), so I have no
idea if they just ignored the report, or they 'silenty' fixed it. I did
not try the latest version.

Vanja Hrustic
SAFER Editor
SAFER - free monthly security newsletter
Subscriptions at http://www.safermag.com