Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » BSCW Insecure Default Installation Vulnerability

BSCW Insecure Default Installation Vulnerability

by Nikola Strahija on January 6th, 2002 BSCW (Basic Support for Cooperative Work) is a web-based groupware application, allowing users to share a workspace via a web interface. It runs on Microsoft Windows NT/2000 systems, as well as a number of Unix variants. The default installation allows users to self-register, potentially allowing untrusted users to access the service.


This may provide a window of opportunity for an untrusted, malicious user to access the service to exploit known issues. One example of an existing issue that may be exploited as a result of untrusted users being able to self-register is BugTraq ID 3776 "BSCW Remote Command Execution Vulnerability".

EXPLOIT

The self-registration interface can be accessed with the following example:

http://your.bscwserver.url/pub/english.cgi?op=rmail


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »