Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Web Servers >> Apache Remote Command Execution via .bat files


Vulnerability Assessment Details

Apache Remote Command Execution via .bat files

Vulnerability Assessment Summary
Tests for presence of Apache Command Execution via .bat vulnerability

Detailed Explanation for this Vulnerability Assessment

The Apache 2.0.x Win32 installation is shipped with a
default script, /cgi-bin/test-cgi.bat, that permits a possible hacker to execute
commands on the Apache server (although it is reported that any .bat file
could open this vulnerability.)

A possible hacker can send a pipe character '|' with commands appended as parameters,
which are then executed by Apache.

Solution:

This bug is fixed in 1.3.24 and 2.0.34-beta, or remove /cgi-bin/test-cgi.bat


Network Security Threat Level: High

Networks Security ID: 4335

Vulnerability Assessment Copyright: This script is Copyright (C) 2002 Matt Moore

Cables, Connectors


Vintage VTECH Equalizer Laptop Computer 90s Works Great W/ Box picture

Vintage VTECH Equalizer Laptop Computer 90s Works Great W/ Box

$89.99



Vintage Texas Instruments TI 99/4A Computer Book User's Reference Guide picture

Vintage Texas Instruments TI 99/4A Computer Book User's Reference Guide

$16.00



Vintage IBM 1390120 Model M Keyboard 1984 W/Cable Clicky Buckling Spring PS2  picture

Vintage IBM 1390120 Model M Keyboard 1984 W/Cable Clicky Buckling Spring PS2

$65.50



NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK picture

NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK

$25.99



Vintage Apple MacWorld Magazine Mousepad picture

Vintage Apple MacWorld Magazine Mousepad

$15.00



Vintage Apple Support Tools Mousepad picture

Vintage Apple Support Tools Mousepad

$15.00



Vintage The Print Shop Ensemble III Windows 95 W/worn Box Broderbund picture

Vintage The Print Shop Ensemble III Windows 95 W/worn Box Broderbund

$29.99



Apple IIe A2S2064 Vintage Personal Computer 128K Enhanced picture

Apple IIe A2S2064 Vintage Personal Computer 128K Enhanced

$200.00



NCR Mechanical Clicky Keyboard Vintage H0150-STD1-12-17 Rare (2 Missing Keys) picture

NCR Mechanical Clicky Keyboard Vintage H0150-STD1-12-17 Rare (2 Missing Keys)

$179.00



VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS picture

VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS

$249.50



Discussions

No Discussions have been posted on this vulnerability.