LPanel Multiple Input Validation Vulnerabilities
BID:13869
Info
LPanel Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 13869 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1877 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery of these issues is credited to Zackarin Smitz. |
| Vulnerable: |
LPanel LPanel 1.596 LPanel LPanel 1.594 LPanel LPanel 1.593 LPanel LPanel 1.59 |
| Not Vulnerable: |
LPanel LPanel 1.597 |
Discussion
LPanel Multiple Input Validation Vulnerabilities
LPanel is prone to multiple input validation vulnerabilities, all of the vulnerabilities require authentication to be exploited. The following issues are reported:
The domain name value passed to the 'domain' parameter of the 'diagnose.php' script is not sufficient sanitized. This may allow an authenticated attacker to reset DNS values for target domains that are controlled by LPanel.
Input passed to the 'close', 'pid', and 'open' parameters of the 'view_ticket.php' script is not sufficiently sanitized. An authenticated attacker may leverage this issue to respond to arbitrary support tickets. Additionally, input passed to the 'pid' parameter may be used to launch HTML injection attacks.
The 'inv' URI parameter, passed to the 'viewreceipt.php' script is not properly sanitized. An authenticated attacker may leverage this issue to view arbitrary receipts.
The 'editdomain' URI parameter, passed to the 'domains.php' script is not properly sanitized. An authenticated attacker may leverage this issue to change DNS information for arbitrary LPanel accounts.
These issues are reported to exist in LPanel versions 1.59 and prior.
LPanel is prone to multiple input validation vulnerabilities, all of the vulnerabilities require authentication to be exploited. The following issues are reported:
The domain name value passed to the 'domain' parameter of the 'diagnose.php' script is not sufficient sanitized. This may allow an authenticated attacker to reset DNS values for target domains that are controlled by LPanel.
Input passed to the 'close', 'pid', and 'open' parameters of the 'view_ticket.php' script is not sufficiently sanitized. An authenticated attacker may leverage this issue to respond to arbitrary support tickets. Additionally, input passed to the 'pid' parameter may be used to launch HTML injection attacks.
The 'inv' URI parameter, passed to the 'viewreceipt.php' script is not properly sanitized. An authenticated attacker may leverage this issue to view arbitrary receipts.
The 'editdomain' URI parameter, passed to the 'domains.php' script is not properly sanitized. An authenticated attacker may leverage this issue to change DNS information for arbitrary LPanel accounts.
These issues are reported to exist in LPanel versions 1.59 and prior.
Exploit / POC
LPanel Multiple Input Validation Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
LPanel Multiple Input Validation Vulnerabilities
Solution:
The vendor has addressed this issue in LPanel version 1.597:
LPanel LPanel 1.59
LPanel LPanel 1.593
LPanel LPanel 1.594
LPanel LPanel 1.596
Solution:
The vendor has addressed this issue in LPanel version 1.597:
LPanel LPanel 1.59
-
LPanel LPanel 1.597
http://lpanel.net/members.php
LPanel LPanel 1.593
-
LPanel LPanel 1.597
http://lpanel.net/members.php
LPanel LPanel 1.594
-
LPanel LPanel 1.597
http://lpanel.net/members.php
LPanel LPanel 1.596
-
LPanel LPanel 1.597
http://lpanel.net/members.php
References
LPanel Multiple Input Validation Vulnerabilities
References:
References:
- LPanel Homepage (LPanel)
- LPanel Release Notes (LPanel)