Multiple Web Wiz Products Remote Information Disclosure Vulnerability
BID:27419
Info
Multiple Web Wiz Products Remote Information Disclosure Vulnerability
| Bugtraq ID: | 27419 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0479 CVE-2008-0480 CVE-2008-0481 CVE-2008-0466 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | The AmnPardaz Security Research Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Web Wiz Rich Text Editor 4.0 Web Wiz NewPad 1.02 Web Wiz Forums 9.07 |
| Not Vulnerable: | |
Discussion
Multiple Web Wiz Products Remote Information Disclosure Vulnerability
Web Wiz Forums, NewsPad, and Rich Text Editor are prone to a remote information-disclosure vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve arbitrary files in the context of the webserver process. Information obtained may aid in further attacks; other attacks are also possible.
This issue affects Forums 9.07, NewsPad 1.02, and Rich Text Editor 4.0; other versions may also be vulnerable.
Web Wiz Forums, NewsPad, and Rich Text Editor are prone to a remote information-disclosure vulnerability because they fail to properly sanitize user-supplied input.
An attacker can exploit this issue to retrieve arbitrary files in the context of the webserver process. Information obtained may aid in further attacks; other attacks are also possible.
This issue affects Forums 9.07, NewsPad 1.02, and Rich Text Editor 4.0; other versions may also be vulnerable.
Exploit / POC
Multiple Web Wiz Products Remote Information Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/RTE_file_browser.asp?look=&sub=\.....\\\.....\\\.....\\http://www.example.com/RTE_file_browser.asp?look=save&sub=\.....\\\.....\\\.....\\\.....\\\.....\\\
Attackers can exploit this issue via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/RTE_file_browser.asp?look=&sub=\.....\\\.....\\\.....\\http://www.example.com/RTE_file_browser.asp?look=save&sub=\.....\\\.....\\\.....\\\.....\\\.....\\\
Solution / Fix
Multiple Web Wiz Products Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Web Wiz Products Remote Information Disclosure Vulnerability
References:
References:
- Web Wiz Forums Homepage (Web Wiz)
- Web Wiz NewsPad Homepage (Web Wiz)
- Web Wiz Rich Text Editor Homepage (Web Wiz)
- Web Wiz Forums Directory traversal ([email protected])
- Web Wiz NewsPad Directory traversal ([email protected])
- Web Wiz Rich Text Editor Directory traversal + HTM/HTML file creation on the ser ([email protected])