PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
BID:15237
Info
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
| Bugtraq ID: | 15237 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2005 12:00AM |
| Updated: | Oct 29 2005 12:00AM |
| Credit: | Discovery is credited to Zeelock <[email protected]>. |
| Vulnerable: |
PHP Advanced Transfer Manager PHP Advanced Transfer Manager 1.30 |
| Not Vulnerable: | |
Discussion
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
PHP Advanced Transfer Manager can allow remote attackers to gain unauthorized access.
Access to sensitive files containing authentication credentials is not restricted, therefore an attacker can simply issue a GET request to obtain a user's password hash. This information can then allow them to successfully authenticate to the service using a cookie.
PHP Advanced Transfer Manager 1.30 is reported to be vulnerable. Other versions may be affected as well.
PHP Advanced Transfer Manager can allow remote attackers to gain unauthorized access.
Access to sensitive files containing authentication credentials is not restricted, therefore an attacker can simply issue a GET request to obtain a user's password hash. This information can then allow them to successfully authenticate to the service using a cookie.
PHP Advanced Transfer Manager 1.30 is reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
An exploit is not required.
A GET request in the following manner can be used to exploit this issue:
http://www.example.com/phpATM/users/<username>
An exploit is not required.
A GET request in the following manner can be used to exploit this issue:
http://www.example.com/phpATM/users/<username>
Solution / Fix
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
References:
References:
- phpATM Homepage (PHP Advanced Transfer Manager)