Involved program: JRUN description: AllaireJRUN2.3 remote execution of arbitrary command vulnerability details: Allaire JRUN Server 2.3 has a security vulnerability, allows remote users to compile and execute arbitrary files on the WEB server as JSP code. If the target file of the URL request uses the prefix servlet, the JSP interpretation execution function is activated. In this case
Involved procedures:
JRUN
Description:
Allaire JRUN 2.3 remote command execution vulnerability
Details:
Allaire's JRUN Server 2.3 has a security vulnerability that allows remote users to compile/execute arbitrary files on the WEB server as JSP code.
If the target file of the URL request uses the prefix "/servlet/", The JSP interpretation execution function is activated. When "../" is used in the target file path requested by the user, it is possible to access files other than the root directory on the WEB server. Using this vulnerability to request a file generated by the user input on the target host will seriously threaten the security of the target host system.
For example:
Http: // jrun: 8000/servlet/com. livesoftware. jrun. plugins. jsp. JSP/.../../path/to/temp.txt
Http: // jrun: 8000/servlet/jsp/.../../path/to/temp.txt
Affected systems:
Allaire JRun 2.3.x
Solution:
Download and install the patch:
Allaire patch jr233p_ASB00_28_29
Http://download.allaire.com/jrun/jr233p_ASB00_28_29.zip
Windows 95/98/NT/2000 and Windows NT Alpha
Allaire patch jr233p_ASB00_28_29tar
Http://download.allaire.com/jrun/jr233p_ASB00_28_29.tar.gz
UNIX/Linux patch-GNU gzip/tar