J-Security Center

Title: Microburst uStorekeeper Remote Arbitrary Commands Vulnerability

Severity: HIGH

Description:

A vulnerability exists in versions of uStorekeeper Online Shopping System from Microburst Technologies.

The script fails to properly validate user-supplied input contained in URLs submitted to the webserver. Remote users can submit file requests and commands containing '/../' sequences in the specified path.

If an attacker appends a command to a submitted URL, followed by a '|' character, the command will be executed with the privilege level of the webserver process, usually 'nobody'.

This also allows a remote user to request files from arbitrary locations on the host filesystem, outside the script's normal directory scope. (Note that target files must otherwise be readable by the webserver process.)

This vulnerability can result in the execution of arbitrary commands as the webserver user, and disclosure of private or sensitive information, which may be exploited to further compromise the security of the vulnerable host.

Affected Products:

  • Microburst uStorekeeper Online Shopping System 1.0.1
  • Microburst uStorekeeper Online Shopping System 1.0.3
  • Microburst uStorekeeper Online Shopping System 1.0.5
  • Microburst uStorekeeper Online Shopping System 1.0.7
  • Microburst uStorekeeper Online Shopping System 1.1.0
  • Microburst uStorekeeper Online Shopping System 1.1.5
  • Microburst uStorekeeper Online Shopping System 1.5.2
  • Microburst uStorekeeper Online Shopping System 1.5.3
  • Microburst uStorekeeper Online Shopping System 1.5.5
  • Microburst uStorekeeper Online Shopping System 1.6.0
  • Microburst uStorekeeper Online Shopping System 1.6.1
  • Microburst uStorekeeper Online Shopping System 1.6.7
  • Microburst uStorekeeper Online Shopping System 1.6.9
  • Microburst uStorekeeper Online Shopping System 1.8.1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.