ContentKeeper Web remote command execution Security Vulnerability
Release date:
Updated on:
Affected Systems:
ContentKeeper Technologies ContentKeeper <125.09
Description:
--------------------------------------------------------------------------------
ContentKeeper is an advanced Internet content filter that allows organizations to monitor and manage access to Internet resources.
ContentKeeper has the remote command execution and permission Escalation Vulnerability. By sending an http post request, you can write any data to the default file with the global read/write permission.
<* Source: Patrick Webster (pwebster@ausgeo.com.au)
Link: http://www.aushack.com/200904-contentkeeper.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ContentKeeper Technologies
--------------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.contentkeeper.com/