PJreview_Neo.cgi Input Validation Hole Discloses Files to Remote Users
|
|
SecurityTracker Alert ID: 1008881
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jan 29 2004
|
Impact: Disclosure of system information, Disclosure of user information
|
Exploit Included: Yes
|
Advisory: Zone-H
|
Description: Zone-h Security Team reported an input validation flaw in the 'PJreview_Neo.cgi' script. A remote user can view files on the target system.
It is reported that the the script does not properly validate user-supplied input in the 'p' variable. A remote user can submit
a specially crafted request containing '../' directory traversal characters to view arbitrary files on the target system with the
privileges of the web service.
A demonstration exploit URL is provided:
http://address/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../..
/etc/passwd
|
Impact: A remote user can view arbitrary files with the privileges of the web server.
|
Solution: No solution was available at the time of this entry. The report indicates that the vendor's web site is no longer available.
|
Cause: Access control error, Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: <zetalabs@zone-h.org>
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 29 Jan 2004 11:43:23 +0100
From: <zetalabs@zone-h.org>
Subject: ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review)
|
ZH2004-02SA (security advisory): PJ CGI Neo review (NeoBoard review) Remote arbitrary file retrieving
Published: 29 january 2004
Released: 29 january 2004
Name: PJ CGI Neo review (NeoBoard review)
Affected Systems: Current version
Issue: Remote file retrieving
Author: Zone-h Security Labs
Vendor: http://www.livepj.com
Description
***********
Zone-h Security Team has discovered a flaw in PJ CGI Neo review (NeoBoard review). There
is a vulnerability in the current version of NeoBoard that allows an attacker to retrieve
arbitrary files from the webserver with its priviledges.
Details
*******
It's possibile for a remote attacker to retrieve any file from a webserver.
For example try this:
http://address/directory/PJreview_Neo.cgi?p=/../../../../../../../../../../../../../../../../etc/pass wd
Solution:
*********
The vendor has not been contacted because his site is unreachable.
Suggestions:
************
Filter the "p" variable.
Zone-h Security Labs - zetalabs@zone-h.org
http://www.zone-h.org/advisories/read/id=3824
|
|