vendor:
Anon Proxy Server
by:
Michael Brooks
7.5
CVSS
HIGH
Multiple Remote System commands execution
78
CWE
Product Name: Anon Proxy Server
Affected Version From: 0.1
Affected Version To: 0.1
Patch Exists: NO
Related CWE:
CPE: a:anon_proxy_server:anon_proxy_server:0.100
Platforms Tested:
2007
Multiple Remote System commands execution in Anon Proxy Server
A flaw exists in diagdns.php in Anon Proxy Server which allows remote attackers to execute arbitrary commands via a crafted request. A virtually identical flaw also exists in diagconnect.php, but it takes longer to execute.
Mitigation:
The best temporary solution is to remove diagdns.php and diagconnect.php. Additionally, using the escapeshellarg() function can provide protection against this vulnerability. Anon Proxy Server will also need to revamp their security as magic_quotes_gpc is being removed in php6.