ATutor Chat Logs Remote Information Disclosure Vulnerability
BID:14832
Info
ATutor Chat Logs Remote Information Disclosure Vulnerability
| Bugtraq ID: | 14832 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2005 12:00AM |
| Updated: | Sep 14 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
ATutor ATutor 1.5.1 |
| Not Vulnerable: | |
Discussion
ATutor Chat Logs Remote Information Disclosure Vulnerability
ATutor is prone to a remote information disclosure vulnerability. This issue is due to a failure in the application to perform proper access validation before granting access to privileged information.
A remote attacker can exploit this vulnerability and make repeated GET requests for the chat logs, effectively retrieving all chat archives. Information obtained may aid an attacker in further attacks.
ATutor is prone to a remote information disclosure vulnerability. This issue is due to a failure in the application to perform proper access validation before granting access to privileged information.
A remote attacker can exploit this vulnerability and make repeated GET requests for the chat logs, effectively retrieving all chat archives. Information obtained may aid an attacker in further attacks.
Exploit / POC
ATutor Chat Logs Remote Information Disclosure Vulnerability
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/atutor/content/chat/2/msgs/1.message
http://www.example.com/atutor/content/chat/2/msgs/2.message
http://www.example.com/atutor/content/chat/2/msgs/3.message
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/atutor/content/chat/2/msgs/1.message
http://www.example.com/atutor/content/chat/2/msgs/2.message
http://www.example.com/atutor/content/chat/2/msgs/3.message
Solution / Fix
ATutor Chat Logs Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ATutor Chat Logs Remote Information Disclosure Vulnerability
References:
References: