SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
BID:19960
CVE-2006-4731 |Info
SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 19960 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4731 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Jan 25 2007 04:26PM |
| Credit: | Chris Murtagh and Richard Patterson of Quickhelp are credited with the discovery of this vulnerability. |
| Vulnerable: |
SQL-Ledger SQL-Ledger 2.6.18 SQL-Ledger SQL-Ledger 2.6.17 LedgerSMB LedgerSMB 1.0 Debian Linux 3.1 |
| Not Vulnerable: |
SQL-Ledger SQL-Ledger 2.6.19 LedgerSMB LedgerSMB 1.0 p1 |
Discussion
SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
SQL-Ledger and LedgerSMB are prone to a remote directory-traversal vulnerability.
An attacker can exploit this issue to include arbitrary files located on the vulnerable computer in the context of the webserver process.
The attacker may be able to use the application's built-in text editor to alter a local file and exploit this issue to execute arbitrary code. This may facilitate a compromise of the vulnerable computer.
SQL-Ledger version 2.6.18 and LedgerSMB version 1.0.0 are vulnerable to this issue.
SQL-Ledger and LedgerSMB are prone to a remote directory-traversal vulnerability.
An attacker can exploit this issue to include arbitrary files located on the vulnerable computer in the context of the webserver process.
The attacker may be able to use the application's built-in text editor to alter a local file and exploit this issue to execute arbitrary code. This may facilitate a compromise of the vulnerable computer.
SQL-Ledger version 2.6.18 and LedgerSMB version 1.0.0 are vulnerable to this issue.
Exploit / POC
SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/path/login.pl?terminal=../css
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/path/login.pl?terminal=../css
Solution / Fix
SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
Solution:
The vendor has released patches to address this issue. Please see the references for more information.
LedgerSMB LedgerSMB 1.0
SQL-Ledger SQL-Ledger 2.6.17
SQL-Ledger SQL-Ledger 2.6.18
Solution:
The vendor has released patches to address this issue. Please see the references for more information.
LedgerSMB LedgerSMB 1.0
-
LedgerSMB LedgerSMB Version 1.0.0 p1
http://sourceforge.net/project/showfiles.php?group_id=175965
SQL-Ledger SQL-Ledger 2.6.17
-
SQL-Ledger SQL-Ledger Version 2.6.19
http://www.sql-ledger.org/cgi-bin/nav.pl?page=source/index.html&title= Download
SQL-Ledger SQL-Ledger 2.6.18
-
SQL-Ledger SQL-Ledger Version 2.6.19
http://www.sql-ledger.org/cgi-bin/nav.pl?page=source/index.html&title= Download
References
SQL-Ledger/LedgerSMB Terminal Parameter Directory Traversal Vulnerability
References:
References:
- LedgerSMB Website (LedgerSMB)
- SQL-Ledger Web Site (SQL-Ledger)
- LedgerSMB 1.0.0 and SQL-Ledger 2.6.18 and earler arbitrary code execution (Chris Travers)