Multiple Web Browsers Handling of Back Ticks Cause Command Execution
24 Nov. 2005
Summary
The web browsers Mozilla Firefox, Mozilla Suite and Opera are vulnerable to local program execution allowing remote attackers to cause the program to execute arbitrary programs.
Vulnerable Systems:
* Mozilla Firefox version 1.0.6
* Mozilla Suite version 1.7.10
* Opera version 8
Immune Systems:
* Opera version 8.51
* Mozilla Firefox version 1.0.7
* Mozilla suite 1.7.12
By opening Mozilla Firefox, Mozilla Suite or the Opera browser with back ticks (`) chars, it is possible to execute arbitrary programs on Linux and UNIX based systems, with the privileges of the running user.
Proof of Concept: Firefox: firefox http://local\`find\`host