Executive brief
Excite for Web Servers (EWS), a search engine software used to index and search website content, contains a critical security flaw. An attacker can exploit this vulnerability to remotely run unauthorized commands on the server hosting the software. This could lead to a complete system takeover, theft of sensitive data, or disruption of web services.
Technical details
Excite for Web Servers (EWS) is vulnerable to an OS command injection flaw. The application fails to properly sanitize user-supplied input containing shell metacharacters before passing it to a system shell for execution. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the web server. Successful exploitation allows for arbitrary command execution with the privileges of the web server process, potentially leading to full system compromise.
Affected products
- Excite Excite for Web Servers (EWS)
Timeline
- 1998-01-01: disclosed