aa33code Authentication Bypass and Local File Include Vulnerabilities
BID:43281
Info
aa33code Authentication Bypass and Local File Include Vulnerabilities
| Bugtraq ID: | 43281 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2009 12:00AM |
| Updated: | Aug 01 2009 12:00AM |
| Credit: | SirGod |
| Vulnerable: |
Josh Hogan aa33code 0.0.1 |
| Not Vulnerable: | |
Discussion
aa33code Authentication Bypass and Local File Include Vulnerabilities
aa33code is prone to an authentication-bypass vulnerability and a local file-include vulnerability because it fails to handle user-supplied input properly.
An attacker can exploit these issues to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process or to gain unauthorized access to the affected application. Other attacks are possible.
aa33code 0.0.1 is vulnerable; other versions may be affected.
aa33code is prone to an authentication-bypass vulnerability and a local file-include vulnerability because it fails to handle user-supplied input properly.
An attacker can exploit these issues to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process or to gain unauthorized access to the affected application. Other attacks are possible.
aa33code 0.0.1 is vulnerable; other versions may be affected.
Exploit / POC
aa33code Authentication Bypass and Local File Include Vulnerabilities
Attackers may exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/[path]/reviews.php?artid=../../../../../../boot.ini%00
http://www.example.com/[path]/artedit/main.php?aa33user=admin
Attackers may exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/[path]/reviews.php?artid=../../../../../../boot.ini%00
http://www.example.com/[path]/artedit/main.php?aa33user=admin
References
aa33code Authentication Bypass and Local File Include Vulnerabilities
References:
References:
- aa33code - Homepage (Josh Hogan)