Executive brief
Webgais, a legacy web-based search interface for the GAIS indexing system, contains a critical security flaw that allows remote attackers to take control of the server. By sending specially crafted requests, an unauthorized user can execute arbitrary commands on the underlying operating system. This could lead to a complete system takeover, data theft, or the disruption of web services.
Technical details
Webgais is vulnerable to a remote command execution flaw, likely stemming from insufficient sanitization of user-supplied input passed to system shells or external processes. An unauthenticated remote attacker can exploit this by submitting malicious parameters through the web interface, leading to the execution of arbitrary commands with the privileges of the web server process. The vulnerability is reachable over the network without prior authentication. While specific code-level details are limited due to the age of the advisory, the impact is a full compromise of the application's integrity and confidentiality.
Affected products
- Webgais Webgais
Timeline
- 1997-07-10: disclosed: Initial publication date in NVD