Leif M. Wright Web Blog Input Validation Flaw Discloses Files to Remote Users
|
|
SecurityTracker Alert ID: 1008872
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jan 28 2004
|
Impact: Disclosure of system information, Disclosure of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: Zone-H
|
Version(s): 1.1
|
Description: Zone-h Security Labs reported a vulnerability in Leif M. Wright's Web Blog. A remote user can view files on the target system.
It is reported that the software does not properly validate the user-supplied 'file' variable. A remote user can supply a specially
crafted URL containing '../' directory traversal characters to view files on the target system with the privileges of the web service.
A
demonstration exploit URL is provided:
http://[target]/directory/blog.cgi?submit=ViewFile&month=[month]&year=[year]&file=/../../../../../../../../../../../../../../../
../etc/passwd
The original advisory is available at:
http://www.zone-h.org/en/advisories/read/id=3822/
|
Impact: A remote user can view files on the target system with the privileges of the web server process.
|
Solution: The vendor has released a fixed version (1.1.5), available at:
http://leifwright.com/scripts/zips/blog.zip
|
Vendor URL: leifwright.com/scripts/Blog.html (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: <zetalabs@zone-h.org>
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 28 Jan 2004 11:21:23 +0100
From: <zetalabs@zone-h.org>
Subject: ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary files
|
ZH2004-01SA (security advisory): Web Blog 1.1 Remote arbitrary files retrieving
Published: 28 january 2004
Released: 28 january 2004
Name: Web Blog
Affected Systems: 1.1
Issue: Remote file retrieving
Author: Zone-h Security Labs
Vendor: http://leifwright.com
Description
***********
Zone-h Security Team has discovered a flaw in Web Blog 1.1. There is a vulnerability in
the current version of Web Blog that allows an attacker to retrieve arbitrary files from
the webserver with its priviledges.
Web Blog is an application to manage blogs.
Details
*******
It's possibile for a remote attacker to retrieve any file from a webserver.
For example try this:
http://address/directory/blog.cgi?submit=ViewFile&month=[month]&year=[year]&file=/../../. ./../../../../../../../../../../../../../etc/passwd
Solution:
*********
The vendor has been contacted and a new version was released.
Zone-h Security Labs - zetalabs@zone-h.org
http://www.zone-h.org/en/advisories/read/id=3822/
|
|