what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New


Posted Nov 14, 2003
Authored by Martin O'Neal

Corsaire Security Advisory - The PeopleSoft PeopleBooks Search CGI is susceptible to argument handling vulnerabilities that allow a remote attacker to gain access to files outside of the webroot.

tags | advisory, remote, cgi, vulnerability
SHA-256 | 54bdecc65f1cc150934bc3dc63cf2ef28eea6cf37d5cea1c26b8bb166ac96381


Change Mirror Download

-- Corsaire Security Advisory --

Title: PeopleSoft PeopleBooks Search CGI multiple argument issues
Date: 04.07.03
Application: PeopleTools 8.20/8.43 and prior
Environment: Various
Author: Martin O'Neal [martin.oneal@corsaire.com]
Audience: General distribution
Reference: c030704-010

-- Scope --

The aim of this document is to clearly define several issues in the
argument handling functionality of the PeopleSoft PeopleBooks Search CGI
application, as supplied by PeopleSoft Ltd. [1].

-- History --

Discovered: 01.07.03 (Martin O'Neal)
Vendor notified: 04.07.03
Document released: 12.11.03

-- Overview --

The PeopleSoft PeopleBooks component provides a CGI based search
application as part of the default installation. Several of the
attributes that are passed into the CGI application allow the
specification of a server-side path. By entering various path values
into this argument it is possible to:

- Access arbitrary files outside of the web servers document root.
- Cause a Denial of Services (DoS) on the web server host.

-- Analysis --

The Search CGI application (psdoccgi.exe) is used within the PeopleBooks
online documentation. This application accepts two arguments, headername
and footername, that allow the selection of header and footer content to
be returned as part of the search results HTML page.

These arguments appear to be checked for basic formatting issues,
however it is still possible to access files outside of the web server
root, such as configuration files, that may contain passwords or other
confidential information.

-- Recommendations --

PeopleSoft have released details of this and other issues under security
rollup vulnerability ID 20031112, which is available to registered users
from the PeopleSoft support site [2].

PeopleSoft recommends that customers address the vulnerability by
applying the following fixes available on PeopleSoft Customer

Release Patch
8.18 8.18.15
8.19 8.19.12
8.20 8.20.03
8.42 8.42.14
8.43 8.43.11

For those who can not implement the patches promptly, as a mitigating
strategy a firewall or other HTTP filtering device can be used to block
queries containing sensitive strings, or as a last resort all access to
the PeopleSoft application can be disabled in entirety.

-- CVE --

The Common Vulnerabilities and Exposures (CVE) project has assigned
Multiple numbers to this issue:

CAN-2003-0626 PeopleSoft PeopleBooks Search CGI arbitrary file read issue
CAN-2003-0627 PeopleSoft PeopleBooks Search CGI DoS issue

These are candidates for inclusion in the CVE list, which standardises
names for security problems (http://cve.mitre.org).

-- References --

[1] http://www.peoplesoft.com
[2] http://www.peoplesoft.com/corp/en/patch_fix/search.jsp

-- Revision --

a. Initial release.
b. Minor detail revisions.
c. Revised to include vendor information.

-- Distribution --

This security advisory may be freely distributed, provided that it
remains unaltered and in its original form.

-- Disclaimer --

The information contained within this advisory is supplied "as-is" with
no warranties or guarantees of fitness of use or otherwise. Corsaire
accepts no responsibility for any damage caused by the use or misuse of
this information.

Copyright 2003 Corsaire Limited. All rights reserved.

Login or Register to add favorites

File Archive:

September 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    23 Files
  • 2
    Sep 2nd
    12 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    0 Files
  • 5
    Sep 5th
    10 Files
  • 6
    Sep 6th
    8 Files
  • 7
    Sep 7th
    30 Files
  • 8
    Sep 8th
    14 Files
  • 9
    Sep 9th
    26 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    5 Files
  • 13
    Sep 13th
    28 Files
  • 14
    Sep 14th
    15 Files
  • 15
    Sep 15th
    17 Files
  • 16
    Sep 16th
    9 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    12 Files
  • 20
    Sep 20th
    15 Files
  • 21
    Sep 21st
    20 Files
  • 22
    Sep 22nd
    13 Files
  • 23
    Sep 23rd
    12 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    30 Files
  • 27
    Sep 27th
    27 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags


packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By