Rule:

--
Sid:
2115
--
Summary:
This event is generated when an attempt is made to exploit a vulnerability in the Mike Bobbit Album.pl cgi application.

--
Impact:
Execution of arbitrary code with the privileges of the user executing the cgi application.

--
Detailed Information:
The MIke Bobbit Album is a Perl CGI script used for managing pictures on a webserver.

A vulnerability exists such that an attacker may execute arbitrary commands on the server when a non-standard configuration file is used.

Affected Systems:
	Mike Bobbit Album 0.61.

--
Attack Scenarios:
Simple.

--
Ease of Attack:
Simple.

--
False Positives:
None Known

--
False Negatives:
None Known

--
Corrective Action:
Upgrade to the latest non-affected version of the software.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

Bugtraq:
http://www.securityfocus.com/bid/7444

--
