SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
BID:10607
Info
SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
| Bugtraq ID: | 10607 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2004 12:00AM |
| Updated: | Jun 25 2004 12:00AM |
| Credit: | Dirk Pirschel <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
SWSoft Confixx Pro 3 SWSoft Confixx Pro 2 |
| Not Vulnerable: | |
Discussion
SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
It is reported that SWSoft Confixx contains an information disclosure vulnerability in its backup script.
A user of Confixx has the ability to backup their files from the server. Reportedly, by issuing a malicious backup request, a regular user of Confixx may cause arbitrary root-accessible files to be backed up as well.
By issuing a malicious backup request, an attacker can download potentially sensitive information from the server. This information may aid the attacker in further attacks.
Reportedly, the restore procedure also contains a flaw that allows an attacker to take ownership of files on the hosting computer. This may allow an attacker to overwrite critical system files, resulting in denial of service conditions, information loss, or potentially even a full system compromise.
It is reported that SWSoft Confixx contains an information disclosure vulnerability in its backup script.
A user of Confixx has the ability to backup their files from the server. Reportedly, by issuing a malicious backup request, a regular user of Confixx may cause arbitrary root-accessible files to be backed up as well.
By issuing a malicious backup request, an attacker can download potentially sensitive information from the server. This information may aid the attacker in further attacks.
Reportedly, the restore procedure also contains a flaw that allows an attacker to take ownership of files on the hosting computer. This may allow an attacker to overwrite critical system files, resulting in denial of service conditions, information loss, or potentially even a full system compromise.
Exploit / POC
SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
Solution:
The vendor has released patches to fix these vulnerabilities:
SWSoft Confixx Pro 3
Solution:
The vendor has released patches to fix these vulnerabilities:
SWSoft Confixx Pro 3
-
SWSoft confixx_update_Pro_3.0.3_mysql3.tgz
For MySQL version 3.x users.
ftp://download1.sw-soft.com/Confixx/ConfixxPro3/3.0.3/confixx_update_P ro_3.0.3_mysql3.tgz -
SWSoft confixx_update_Pro_3.0.3_mysql4.tgz
For MySQL version 4.x users.
ftp://download1.sw-soft.com/Confixx/ConfixxPro3/3.0.3/confixx_update_P ro_3.0.3_mysql4.tgz -
SWSoft confixx_v3.0.3_hotfix_002.sh.gz
ftp://download1.sw-soft.com/Confixx/ConfixxPro3/3.0.3/confixx_v3.0.3_h otfix_002.sh.gz -
SWSoft confixx_v3.0.3_mysql3_hotfix_003.sh.gz
For MySQL version 3.x users.
ftp://download1.sw-soft.com/Confixx/ConfixxPro3/3.0.3/confixx_v3.0.3_m ysql3_hotfix_003.sh.gz -
SWSoft confixx_v3.0.3_mysql4_hotfix_003.sh.gz
For MySQL version 4.x users.
ftp://download1.sw-soft.com/Confixx/ConfixxPro3/3.0.3/confixx_v3.0.3_m ysql4_hotfix_003.sh.gz
References
SWSoft Confixx Backup And Restore Script Information Disclosure And File Ownership Vulnerabilities
References:
References:
- Confixx 3.0 hotfix #002 - RELEASE NOTES (SWSoft)
- Confixx 3.0 hotfix #003 - RELEASE NOTES (SWSoft)
- Confixx Homepage (SWSoft)
- Security hole in Confixx backup script (Dirk Pirschel)
- Security hole in Confixx backup script (Dirk Pirschel)
- Security hole in Confixx backup script (Dirk Pirschel)